CMS MADE SIMPLE FORGE

CMS Made Simple Core

 

[#12567] Security issue caused by using older versions of Smarty

avatar
Created By: z (altman)
Date Submitted: Fri Oct 21 12:04:55 -0400 2022

Assigned To: CMS Made Simple Foundation (cmsmsfoundation)
Version: 2.2.16
CMSMS Version: 2.2.16
Severity: Critical
Resolution: None
State: Open
Summary:
Security issue caused by using older versions of Smarty
Detailed Description:
CMSMS use Smarty v3.1.31 and enable Smarty security mode. But there are several
sandbox bypass vulnerabilities in Smarty v3.1.31, this can cause users with
template modification capabilities to bypass the sandbox and attack. Developers
should upgrade Smarty to the latest version.


History