Smarty before 3.1.39 allows a Sandbox Escape because $smarty.template_object can be accessed in sandbox mode.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Smarty | Smarty | * | 3.1.39 (excluding) |
Smarty3 | Ubuntu | bionic | * |
Smarty3 | Ubuntu | esm-apps/focal | * |
Smarty3 | Ubuntu | esm-apps/xenial | * |
Smarty3 | Ubuntu | focal | * |
Smarty3 | Ubuntu | groovy | * |
Smarty3 | Ubuntu | hirsute | * |
Smarty3 | Ubuntu | trusty | * |
Smarty3 | Ubuntu | upstream | * |
Smarty3 | Ubuntu | xenial | * |