USN-8272-1: Smarty vulnerability
Source: Ubuntu
Published:
<p>Smarty could be made to run malicious JavaScript in the user's browser if it received specially crafted input.</p> <p>Takuya Aramaki discovered that Smarty did not properly escape JavaScript code. An attacker could possibly use this issue to conduct a cross-site scripting attack.</p> <p>Takuya Ar