Impact
This is a code injection vulnerability that can lead to arbitrary PHP code execution in applications that let less-trusted users edit View Parser templates. Applications are impacted when they:
- allow users to edit template source, such as an online email template, and
- render that source with unrestricted Parser conditional tags.
Applications using only developer-controlled templates are not affected.
Patches
Upgrade to v4.7.5 or later.
Applications must enable Config\View::$restrictParserConditionals or the per-render restrictConditionals option for every affected template. Upgrading alone does not remove the exposure.
Workarounds
- Limit template editing to users trusted to execute PHP on the server.
- Avoid rendering less-trusted template source with the Parser until the conditional restriction is enabled.
References
Impact
This is a code injection vulnerability that can lead to arbitrary PHP code execution in applications that let less-trusted users edit View Parser templates. Applications are impacted when they:
Applications using only developer-controlled templates are not affected.
Patches
Upgrade to v4.7.5 or later.
Applications must enable
Config\View::$restrictParserConditionalsor the per-renderrestrictConditionalsoption for every affected template. Upgrading alone does not remove the exposure.Workarounds
References