In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS. A web page that uses smarty_function_mailto, and that could be parameterized using GET or POST input parameters, could allow injection of JavaScript code by a user.
| Software | From | Fixed in |
|---|---|---|
| smarty / smarty | - | 3.1.47 |
| smarty / smarty | 4.0.0 | 4.2.1 |
| debian / debian_linux | 10.0 | 10.0.x |
smarty / smarty
|
- | 3.1.47 |
smarty / smarty
|
4.0.0 | 4.2.1 |