VYPR
High severity8.8NVD Advisory· Published May 24, 2022· Updated Jun 17, 2026

CVE-2022-29221

CVE-2022-29221

Description

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.45 and 4.1.1, template authors could inject php code by choosing a malicious {block} name or {include} file name. Sites that cannot fully trust template authors should upgrade to versions 3.1.45 or 4.1.1 to receive a patch for this issue. There are currently no known workarounds.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
smarty/smartyPackagist
< 3.1.453.1.45
smarty/smartyPackagist
>= 4.0.0, < 4.1.14.1.1

Affected products

8
  • Smarty/Smarty2 versions
    cpe:2.3:a:smarty:smarty:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:smarty:smarty:*:*:*:*:*:*:*:*range: <3.1.45
    • (no CPE)range: < 3.1.45
  • Debian/linux3 versions
    cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
  • ghsa-coords
    Range: < 3.1.45

Patches

Vulnerability mechanics

References

14

News mentions

0

No linked articles in our index yet.