VYPR
High severity8.1NVD Advisory· Published Jan 10, 2022· Updated Jun 17, 2026

CVE-2021-29454

CVE-2021-29454

Description

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.42 and 4.0.2, template authors could run arbitrary PHP code by crafting a malicious math string. If a math string was passed through as user provided data to the math function, external users could run arbitrary PHP code by crafting a malicious math string. Users should upgrade to version 3.1.42 or 4.0.2 to receive a patch.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
smarty/smartyPackagist
< 3.1.423.1.42
smarty/smartyPackagist
>= 4.0.0, < 4.0.24.0.2

Affected products

8
  • Smarty/Smarty2 versions
    cpe:2.3:a:smarty:smarty:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:smarty:smarty:*:*:*:*:*:*:*:*range: <3.1.42
    • (no CPE)range: < 3.1.42
  • Debian/linux3 versions
    cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
  • ghsa-coords
    Range: < 3.1.42

Patches

Vulnerability mechanics

References

16

News mentions

0

No linked articles in our index yet.