CVE

CVE-2021-26120

CVE-2021-26120

Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.

Source: CVE-2021-26120

Exit mobile version