CVE-2018-13982: Path Traversal
SmartySecurity::isTrustedResourceDir() in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insufficient template code sanitization. This allows attackers controlling the executed template code to bypass the trusted directory security restriction and read arbitrary files.
Other sources
SmartySecurity::isTrustedResourceDir() in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insufficient template code sanitization. This allows attackers controlling the executed template code to bypass the trusted directory security restriction and read arbitrary files.
Trusted-Directory Bypass via Path Traversal
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-13982?
CVE-2018-13982 is classified as a high severity vulnerability due to its potential for arbitrary file access.
How do I fix CVE-2018-13982?
To fix CVE-2018-13982, upgrade Smarty to version 3.1.33 or later.
What types of attacks can exploit CVE-2018-13982?
CVE-2018-13982 can be exploited for path traversal attacks allowing attackers to read sensitive files on the server.
Which versions of Smarty are affected by CVE-2018-13982?
Smarty versions prior to 3.1.33 are affected by CVE-2018-13982.
What is the impact of CVE-2018-13982 on data security?
The impact of CVE-2018-13982 includes potential unauthorized access to sensitive files, leading to data breaches.