CVE-2018-25047: Debian Linux

Medium severity, CVSS 5.4. EPSS: 1.1% chance of exploitation in the next 30 days.

In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS. A web page that uses smarty_function_mailto, and that could be parameterized using GET or POST input parameters, could allow injection of JavaScript code by a user.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Smarty Smarty: before 3.1.47 (fixed in 3.1.47); from 4.0.0, before 4.2.1 (fixed in 4.2.1)

Published 2022-09-15. Last modified 2026-06-17.