First published: Mon Oct 01 2012(Updated: )
Cross-site scripting (XSS) vulnerability in the `SmartyException` class in Smarty (aka smarty-php) before 3.1.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors that trigger a Smarty exception.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/smarty/smarty | <3.1.12 | 3.1.12 |
Smarty | =1.0 | |
Smarty | =1.0a | |
Smarty | =1.0b | |
Smarty | =1.1.0 | |
Smarty | =1.2.0 | |
Smarty | =1.2.1 | |
Smarty | =1.2.2 | |
Smarty | =1.3.0 | |
Smarty | =1.3.1 | |
Smarty | =1.3.2 | |
Smarty | =1.4.0 | |
Smarty | =1.4.0-b1 | |
Smarty | =1.4.0-b2 | |
Smarty | =1.4.1 | |
Smarty | =1.4.2 | |
Smarty | =1.4.3 | |
Smarty | =1.4.4 | |
Smarty | =1.4.5 | |
Smarty | =1.4.6 | |
Smarty | =1.5.0 | |
Smarty | =1.5.1 | |
Smarty | =1.5.2 | |
Smarty | =2.0.0 | |
Smarty | =2.0.1 | |
Smarty | =2.1.0 | |
Smarty | =2.1.1 | |
Smarty | =2.2.0 | |
Smarty | =2.3.0 | |
Smarty | =2.3.1 | |
Smarty | =2.4.0 | |
Smarty | =2.4.1 | |
Smarty | =2.4.2 | |
Smarty | =2.5.0 | |
Smarty | =2.5.0-rc1 | |
Smarty | =2.5.0-rc2 | |
Smarty | =2.6.0 | |
Smarty | =2.6.0-rc1 | |
Smarty | =2.6.0-rc2 | |
Smarty | =2.6.0-rc3 | |
Smarty | =2.6.1 | |
Smarty | =2.6.2 | |
Smarty | =2.6.3 | |
Smarty | =2.6.4 | |
Smarty | =2.6.5 | |
Smarty | =2.6.6 | |
Smarty | =2.6.7 | |
Smarty | =2.6.9 | |
Smarty | =2.6.10 | |
Smarty | =2.6.11 | |
Smarty | =2.6.12 | |
Smarty | =2.6.13 | |
Smarty | =2.6.14 | |
Smarty | =2.6.15 | |
Smarty | =2.6.16 | |
Smarty | =2.6.17 | |
Smarty | =2.6.18 | |
Smarty | =2.6.20 | |
Smarty | =2.6.22 | |
Smarty | =2.6.24 | |
Smarty | =2.6.25 | |
Smarty | =2.6.26 | |
Smarty | =3.0.0 | |
Smarty | =3.0.0-beta4 | |
Smarty | =3.0.0-beta5 | |
Smarty | =3.0.0-beta6 | |
Smarty | =3.0.0-beta7 | |
Smarty | =3.0.0-beta8 | |
Smarty | =3.0.0-rc1 | |
Smarty | =3.0.0-rc2 | |
Smarty | =3.0.0-rc3 | |
Smarty | =3.0.0-rc4 | |
Smarty | =3.0.1 | |
Smarty | =3.0.2 | |
Smarty | =3.0.3 | |
Smarty | =3.0.4 | |
Smarty | =3.0.5 | |
Smarty | =3.0.6 | |
Smarty | =3.0.7 | |
Smarty | =3.1-rc1 | |
Smarty | =3.1.0 | |
Smarty | =3.1.1 | |
Smarty | =3.1.2 | |
Smarty | =3.1.3 | |
Smarty | =3.1.4 | |
Smarty | =3.1.5 | |
Smarty | =3.1.6 | |
Smarty | =3.1.7 | |
Smarty | =3.1.8 | |
Smarty | =3.1.9 | |
Smarty | =3.1.10 | |
Smarty | =3.1.11 | |
Smarty | =3.1.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4437 has been rated as a medium severity vulnerability due to the potential for cross-site scripting attacks.
To fix CVE-2012-4437, upgrade to Smarty version 3.1.12 or later.
CVE-2012-4437 is a cross-site scripting (XSS) vulnerability.
CVE-2012-4437 affects Smarty versions prior to 3.1.12, including various versions 1.x and 2.x.
An attacker can inject arbitrary web scripts or HTML into affected Smarty applications, potentially compromising user data or executing malicious scripts.