Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Smartstorenet CRITICAL 9.1
CVE-2020-36364

An issue was discovered in Smartstore (aka SmartStoreNET) before 4.1.0. Administration/Controllers/ImportController.cs allows path traversal (for cop…

Fix: 4.1.0+
Fix from $2,300 2021-05-19
Smartstorenet MEDIUM 6.1
CVE-2020-36365

Smartstore (aka SmartStoreNET) before 4.1.0 allows CommonController.ClearCache, ClearDatabaseCache, RestartApplication, and ScheduleTaskController.Ed…

Fix: 4.1.0+
Fix from $1,600 2021-05-19
Smartstore CRITICAL 9.8
CVE-2021-32607EPSS 33%

An issue was discovered in Smartstore (aka SmartStoreNET) through 4.1.1. Views/PrivateMessages/View.cshtml does not call HtmlUtils.SanitizeHtml on a …

Fix: after 4.1.1
Fix from $2,300 2021-05-12
Smartstore CRITICAL 9.8
CVE-2021-32608EPSS 33%

An issue was discovered in Smartstore (aka SmartStoreNET) through 4.1.1. Views/Boards/Partials/_ForumPost.cshtml does not call HtmlUtils.SanitizeHtml…

Fix: after 4.1.1
Fix from $2,300 2021-05-12
Smartstorenet HIGH 8.8
CVE-2020-27997

An issue was discovered in SmartStoreNET before 4.1.0. Lack of Cross Site Request Forgery (CSRF) protection may lead to elevation of privileges (e.g.…

Fix: 4.1.0+
Fix from $1,950 2021-02-19
Smartstorenet HIGH 8.8
CVE-2020-27996

An issue was discovered in SmartStoreNET before 4.0.1. It does not properly consider the need for a CustomModelPartAttribute decoration in certain Mo…

Fix: 4.0.1+
Fix from $1,950 2020-10-29
Smartstore CRITICAL 9.8
CVE-2020-15243

Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore shops in version 4.0.0 & 4.0.1 …

Mitigation only
Fix from $2,300 2020-10-08