CVE-2018-25047 | Smarty up to 3.1.46/4.2.0 function.mailto.php smarty_function_mailto cross site scripting (Issue 454 / Nessus ID 211501)
A vulnerability, which was classified as problematic, has been found in Smarty up to 3.1.46/4.2.0. Affected by this issue is the function smarty_function_mailto of the file libs/plugins/function.mailto.php. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2018-25047. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.