Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Takaram

#41135of 56,330
7.1Total CVSS
Vulnerabilities · 1
PT-2023-21728
7.1
2023-03-28
Smarty · Smarty · CVE-2023-28447
**Name of the Vulnerable Software and Affected Versions** Smarty versions prior to 3.1.48 Smarty versions prior to 4.3.1 **Description** The issue is related to improper escaping of JavaScript code in the Smarty template engine for PHP. An attacker could exploit this to execute arbitrary JavaScript code in the context of the user's browser session, potentially leading to unauthorized access to sensitive user data, manipulation of the web application's behavior, or unauthorized actions performed on behalf of the user. **Recommendations** To resolve this issue, users are advised to upgrade to either version 3.1.48 or version 4.3.1. For versions prior to 3.1.48, upgrade to version 3.1.48. For versions prior to 4.3.1, upgrade to version 4.3.1.