Monday, October 5, 2026
EN

Subscribe in your feed reader — pick your desks:

https://php-net.pro/en/news/feed.atom

php-net.pro · the dev news broadsheet

The Dev Dispatch

PHP · Security

Smarty PHP fixes a cache-dependent route to remote code execution

Smarty PHP releases before 4.5.8 and 5.8.5 can escalate a template injection issue from cross-site scripting to remote code execution under specific conditions. The attacker must control an unescaped rendered value. The template must use {extends}, and rendered-template caching must be enabled. The cache option is disabled by default. Updating to a fixed release removes the issue.

Read the original source ↗

Rate this article: 0

Comments

No comments yet — be the first.