CVE-2018-13982: Debian Linux
High severity, CVSS 7.5. EPSS: 3.5% chance of exploitation in the next 30 days.
Smarty_Security::isTrustedResourceDir() in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insufficient template code sanitization. This allows attackers controlling the executed template code to bypass the trusted directory security restriction and read arbitrary files.
Affected products
Published 2018-09-18. Last modified 2026-06-17.