The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| smarty/smarty(Packagist) | 0 | 3.0.7 | N/A |
CVSS Metrics