CVE-2020-15243
Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.
NVD · uneditedAffected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore shops in version 4.0.0 & 4.0.1 which have installed and activated the Web API plugin. Users of Smartstore 4.0.0 and 4.0.1 must merge their repository with 4.0.x or overwrite the file SmartStore.Web.Framework in the */bin* directory of the deployed shop with this file. As a workaround without updating uninstall the Web API plugin to close this vulnerability.
Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.
dbcve analysis · high confidenceSmartstore versions 4.0.0 and 4.0.1 have a missing WebApi Authentication attribute in the SmartStore.Web.Framework component. This allows unauthenticated access to Web API endpoints when the Web API plugin is installed and activated, exposing sensitive shop functionality without proper authentication.
Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.
Affected products & versions What the vendor confirmedThe version ranges the vendor confirmed as vulnerable. If your version sits inside a range here, treat yourself as exposed until you have upgraded.
NVD · CPE data= 4.0.0= 4.0.1CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.
From the vector- Attack vector
- Network
- Complexity
- Low
- Privileges
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.
dbcve checksWork through these to decide whether this CVE applies to you.
-
Identify Smartstore versionCheck the installed version via the admin dashboard (typically visible in the footer or under System > Information), or inspect the bin/SmartStore.Core.dll version propertiesAffected if Version is 4.0.0 or 4.0.1 exactly (note: version 4.0.2 and later are NOT affected)
-
Locate the WebApi pluginNavigate to Admin > Plugins > All Plugins and search for 'Web API' or 'SmartStore.WebApi', or inspect the /Plugins directory for a WebApi-related folderAffected if A WebApi plugin folder exists in the /Plugins directory or is listed in the admin plugins page
-
Verify WebApi plugin is activatedIn the admin panel under Plugins > All Plugins, check if the Web API plugin status shows as 'Installed and active' or check the Plugins.config/xml file for an active WebApi entryAffected if The Web API plugin shows as installed and enabled/active in the system
-
Confirm missing authentication attributeInspect the compiled SmartStore.Web.Framework.dll in the /bin folder using a .NET decompiler (such as dotPeek or ILSpy) and locate the WebApi controller classes; check if they lack the [Authorized] attribute or a custom authentication filterAffected if WebApi controllers are publicly accessible without any [Authorized] attribute or authentication requirement, indicating the missing security attribute
-
Test unauthenticated API access (optional)Using a tool like Postman or curl, send a GET request to a known WebApi endpoint (such as /api/v1/[controller] without providing any authentication headers)Affected if The API returns HTTP 200 with data rather than HTTP 401 Unauthorized, confirming unauthenticated access is possible
You are affected if running Smartstore 4.0.0 or 4.0.1 AND the Web API plugin is installed and active, allowing unauthenticated access to sensitive API endpoints.
Generated from the published advisory. Verify against your own configuration.
Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.
dbcve · scopedApply the vendor fix by either merging repository changes from version 4.0.x or replacing the SmartStore.Web.Framework DLL in the */bin* directory. Alternatively, uninstall the Web API plugin as a workaround until the patch can be applied.
4.0.x branch (e.g., SmartStoreNET 4.0.2 or later)
- Ensure you have a complete backup of your Smartstore installation and database before proceeding
- Identify whether the Web API plugin is installed and activated in your Smartstore 4.0.0 or 4.0.1 installation
- If you have source code access: merge your repository with the 4.0.x branch (e.g., SmartStoreNET/SmartStoreNET on GitHub)
- If you do not have source code: download the updated SmartStore.Web.Framework.dll file from the Smartstore 4.0.x release and replace the existing file in the /bin directory of your deployed shop
- After applying the fix, verify that the Web API functionality still works correctly
- Test authentication on your Web API endpoints to confirm the vulnerability is remediated
- Alternatively (workaround only): Navigate to the Plugins section in the Smartstore admin panel, find the Web API plugin, and uninstall it to close the vulnerability without updating
Generated from the published advisory — verify against the referenced sources before acting.
- Consultation2.0 h
- Implementation2.0 h
- Testing2.0 h
- Review / QA1.0 h
An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $1,984.
Scan for this in your stack
Free · runs locallyCheck whether your project pulls in CVE-2020-15243 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.
References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.
Primary sourcesPractitioner notes
ContributedPeer-ranked notes from engineers who’ve handled CVE-2020-15243 in production — separate from our analysis above.
The advisory tells you what broke. It rarely tells you what actually worked. If you’ve dealt with this one, that detail is what the next engineer is searching for.
- The version that genuinely resolved it — not the one the vendor claimed
- A config change or rule that shut the vector down
- A gotcha in the upgrade path that cost you an afternoon
No notes yet
Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.
A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.
- Verified mitigations, workarounds, and config changes
- Version or environment caveats, and links to real fixes
- No weaponised exploit code, or anything meant to cause harm
- No spam, self-promotion, credentials, or personal data