CVE-2018-13982

HIGH

Smarty < 3.1.33 - Path Traversal via Trusted Resource Directory Bypass

Title source: llm
STIX 2.1

Description

Smarty_Security::isTrustedResourceDir() in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insufficient template code sanitization. This allows attackers controlling the executed template code to bypass the trusted directory security restriction and read arbitrary files.

Scores

CVSS v3 7.5
EPSS 0.0346
EPSS Percentile 87.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (3)
debian/debian_linux 9.0
smarty/smarty < 3.1.33
smarty/smarty 0 - 3.1.33Packagist
Published Sep 18, 2018
Tracked Since Feb 18, 2026