Critical severity9.8NVD Advisory· Published Jan 3, 2018· Updated Jun 17, 2026
CVE-2017-1000480
CVE-2017-1000480
Description
Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling fetch() or display() functions on custom resources that does not sanitize template name.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
smarty/smartyPackagist | >= 3, < 3.1.32 | 3.1.32 |
Affected products
2Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-9m49-vhwv-422gghsaADVISORY
- github.com/smarty-php/smarty/blob/master/change_log.txtnvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2017-1000480ghsaADVISORY
- lists.debian.org/debian-lts-announce/2018/01/msg00023.htmlnvdWEB
- lists.debian.org/debian-lts-announce/2018/02/msg00000.htmlnvdWEB
- www.debian.org/security/2018/dsa-4094nvdWEB
News mentions
0No linked articles in our index yet.