CVE-2018-25047 | Smarty up to 3.1.46/4.2.0 function.mailto.php smarty_function_mailto cross site scripting (Issue 454 / Nessus ID 211501)
A vulnerability was found in Smarty up to 3.1.46/4.2.0. It has been rated as problematic. The affected element is the function smarty_function_mailto of the file libs/plugins/function.mailto.php. This manipulation causes cross site scripting.
This vulnerability is handled as CVE-2018-25047. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.