Security Risk: 
Not Critical
Vulnerability: 
Other
Affected Versions: 

CiviCRM Versions prior to 4.7.26 and 4.6.33

Fixed Versions: 

CiviCRM Version 4.7.26 and 4.6.33

Publication Date: 
Wednesday, November 1, 2017
Description: 

As part of CiviCRM's defense in depth program, we have upgraded Smarty following an announcement by them that one of the functions in the Smarty templating engine potentially allowed for shell injection.

Despite this vulnerability in the Smarty library, CiviCRM's usage of Smarty appears to prevent such shell injection vulnerabilities.

Solutions: 

Upgrade CiviCRM to the latest version

  • 4.7.26
  • 4.6.33

or later

Or apply the following patch 

 

Credits: 

Seamus Lee of Australian Greens for reporting and Fixing the issue

References: