CVE-2021-26120

Publication date

2021-02-22 01:38:15

Family

mitre

State

PUBLISHED

Description

Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.