Smartstore Smartstorenet vulnerabilities
5 known vulnerabilities affecting smartstore/smartstorenet.
Total CVEs
5
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2020-15243P3CRITICALCVSS 9.8v>= 4.0.0, <= 4.0.12020-10-08
CVE-2020-15243 [CRITICAL] CWE-287 CVE-2020-15243: Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability a
Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore shops in version 4.0.0 & 4.0.1 which have installed and activated the Web API plugin. Users of Smartstore 4.0.0 and 4.0.1 must merge their repository with 4.0.x or overwrite the file SmartStore.Web.Framework in the */bin* directory
nvd
CVE-2020-36365P3MEDIUMCVSS 6.1PoCfixed in 4.1.02021-05-19
CVE-2020-36365 [MEDIUM] CWE-601 CVE-2020-36365: Smartstore (aka SmartStoreNET) before 4.1.0 allows CommonController.ClearCache, ClearDatabaseCache,
Smartstore (aka SmartStoreNET) before 4.1.0 allows CommonController.ClearCache, ClearDatabaseCache, RestartApplication, and ScheduleTaskController.Edit open redirect.
nvd
CVE-2020-27996P3HIGHCVSS 8.8fixed in 4.0.12020-10-29
CVE-2020-27996 [HIGH] CVE-2020-27996: An issue was discovered in SmartStoreNET before 4.0.1. It does not properly consider the need for a
An issue was discovered in SmartStoreNET before 4.0.1. It does not properly consider the need for a CustomModelPartAttribute decoration in certain ModelBase.CustomProperties situations.
nvd
CVE-2020-36364P3CRITICALCVSS 9.1fixed in 4.1.02021-05-19
CVE-2020-36364 [CRITICAL] CWE-22 CVE-2020-36364: An issue was discovered in Smartstore (aka SmartStoreNET) before 4.1.0. Administration/Controllers/I
An issue was discovered in Smartstore (aka SmartStoreNET) before 4.1.0. Administration/Controllers/ImportController.cs allows path traversal (for copy and delete actions) in the ImportController.Create method via a TempFileName field.
nvd
CVE-2020-27997P3HIGHCVSS 8.8fixed in 4.1.02021-02-19
CVE-2020-27997 [HIGH] CWE-352 CVE-2020-27997: An issue was discovered in SmartStoreNET before 4.1.0. Lack of Cross Site Request Forgery (CSRF) pro
An issue was discovered in SmartStoreNET before 4.1.0. Lack of Cross Site Request Forgery (CSRF) protection may lead to elevation of privileges (e.g., /admin/customer/create to create an admin account).
nvd