CVE-2023-28447: Cross site scripting vulnerability in Javascript escaping in smarty/smarty
Impact An attacker could exploit this vulnerability to execute arbitrary JavaScript code in the context of the user's browser session. This may lead to unauthorized access to sensitive user data, manipulation of the web application's behavior, or unauthorized actions performed on behalf of the user.
Patches Please upgrade to the most recent version of Smarty v3 or v4.
For more information If you have any questions or comments about this advisory please open an issue in the Smarty repo
Other sources
Cross site scripting vulnerability in Javascript escaping
Smarty is a template engine for PHP. In affected versions smarty did not properly escape javascript code. An attacker could exploit this vulnerability to execute arbitrary JavaScript code in the context of the user's browser session. This may lead to unauthorized access to sensitive user data, manipulation of the web application's behavior, or unauthorized actions performed on behalf of the user. Users are advised to upgrade to either version 3.1.48 or to 4.3.1 to resolve this issue. There are no known workarounds for this vulnerability.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28447?
CVE-2023-28447 has a high severity due to the potential for arbitrary JavaScript execution in the user's browser.
How do I fix CVE-2023-28447?
To fix CVE-2023-28447, upgrade Smarty to version 3.1.48 or 4.3.1 or later.
Which versions of Smarty are affected by CVE-2023-28447?
Versions 3.1.48, and 4.0.0 up to 4.1.1 of Smarty are affected by CVE-2023-28447.
What type of attack does CVE-2023-28447 enable?
CVE-2023-28447 allows attackers to execute arbitrary JavaScript code in the context of the user's browser session.
Is CVE-2023-28447 related to Fedora distributions?
Yes, CVE-2023-28447 affects Fedora versions 36, 37, and 38 among other platforms.