Smarty before 3.0.0, when security is enabled, does not prevent access to the (1) dynamic and (2) private object members of an assigned object, which has unspecified impact and remote attack vectors.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-10-03T16:21:05

Updated: 2022-10-03T16:21:05

Reserved: 2022-10-03T00:00:00


Link: CVE-2010-4723

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2011-02-03T17:00:01.947

Modified: 2011-02-15T05:00:00.000


Link: CVE-2010-4723

JSON object: View

cve-icon Redhat Information

No data.

CWE