CVE-2018-25047: XSS
In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS. A web page that uses smartyfunctionmailto, and that could be parameterized using GET or POST input parameters, could allow injection of JavaScript code by a user.
Other sources
smartyfunctionmailto - JavaScript injection in eval function
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-25047?
CVE-2018-25047 is considered to have a high severity due to its potential for allowing cross-site scripting (XSS) attacks.
How do I fix CVE-2018-25047?
To fix CVE-2018-25047, upgrade Smarty to version 3.1.48 or 4.2.1 or later.
Which versions of Smarty are affected by CVE-2018-25047?
CVE-2018-25047 affects Smarty versions prior to 3.1.48 and versions between 4.0.0 and 4.2.1.
What types of attacks can CVE-2018-25047 facilitate?
CVE-2018-25047 can facilitate cross-site scripting (XSS) attacks by allowing the injection of JavaScript code.
Are there any specific software packages vulnerable due to CVE-2018-25047?
Vulnerable software packages include specified versions of Smarty 3.x and 4.x, particularly under Debian systems.