CRITICAL9.8
GHSA-mh9j-v6mq-pfch
Path manipulation in matyhtf/framework
Quick fix
GHSA-mh9j-v6mq-pfch — matyhtf/framework: upgrade to the fixed version with the command below.
composer require matyhtf/framework:^3.0.6Details
matyhtf framework v3.0.5 is affected by a path manipulation vulnerability in Smarty.class.php. The issue was fixed in version 3.0.6.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/matyhtf/framework
Introduced in:
0Fixed in: 3.0.6Fix
composer require matyhtf/framework:^3.0.6References
- https://nvd.nist.gov/vuln/detail/CVE-2021-43676[ADVISORY]
- https://github.com/matyhtf/framework/issues/206[WEB]
- https://github.com/matyhtf/framework/commit/25084603b7ea771eebe263d39744fe6abf1f8d61[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/matyhtf/framework/CVE-2021-43676.yaml[WEB]
- https://github.com/advisories/GHSA-mh9j-v6mq-pfch[ADVISORY]
- https://github.com/matyhtf/framework[PACKAGE]