Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2020-36365

Disclosure Date: May 19, 2021 (last updated February 22, 2025)
Smartstore (aka SmartStoreNET) before 4.1.0 allows CommonController.ClearCache, ClearDatabaseCache, RestartApplication, and ScheduleTaskController.Edit open redirect.
Attacker Value
Unknown

CVE-2020-36364

Disclosure Date: May 19, 2021 (last updated February 22, 2025)
An issue was discovered in Smartstore (aka SmartStoreNET) before 4.1.0. Administration/Controllers/ImportController.cs allows path traversal (for copy and delete actions) in the ImportController.Create method via a TempFileName field.
Attacker Value
Unknown

CVE-2021-32607

Disclosure Date: May 12, 2021 (last updated November 28, 2024)
An issue was discovered in Smartstore (aka SmartStoreNET) through 4.1.1. Views/PrivateMessages/View.cshtml does not call HtmlUtils.SanitizeHtml on a private message.
Attacker Value
Unknown

CVE-2021-32608

Disclosure Date: May 12, 2021 (last updated November 28, 2024)
An issue was discovered in Smartstore (aka SmartStoreNET) through 4.1.1. Views/Boards/Partials/_ForumPost.cshtml does not call HtmlUtils.SanitizeHtml on certain text for a forum post.
Attacker Value
Unknown

CVE-2020-27997

Disclosure Date: February 19, 2021 (last updated February 22, 2025)
An issue was discovered in SmartStoreNET before 4.1.0. Lack of Cross Site Request Forgery (CSRF) protection may lead to elevation of privileges (e.g., /admin/customer/create to create an admin account).
Attacker Value
Unknown

CVE-2020-27996

Disclosure Date: October 29, 2020 (last updated November 28, 2024)
An issue was discovered in SmartStoreNET before 4.0.1. It does not properly consider the need for a CustomModelPartAttribute decoration in certain ModelBase.CustomProperties situations.
Attacker Value
Unknown

CVE-2020-15243

Disclosure Date: October 08, 2020 (last updated February 22, 2025)
Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore shops in version 4.0.0 & 4.0.1 which have installed and activated the Web API plugin. Users of Smartstore 4.0.0 and 4.0.1 must merge their repository with 4.0.x or overwrite the file SmartStore.Web.Framework in the */bin* directory of the deployed shop with this file. As a workaround without updating uninstall the Web API plugin to close this vulnerability.