ZeroHour

Vulnerabilities

7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-36364
+1 in the same advisory: …36365
An issue was discovered in Smartstore (aka SmartStoreNET) before 4.1.0.

An issue was discovered in Smartstore (aka SmartStoreNET) before 4.1.0. Administration/Controllers/ImportController.cs allows path traversal (for copy and delete actions) in the ImportController.Create method via a TempFileName field.

NVD description · AI analysis pending
9.1
group max
2% PoC
  • smartstore smartstorenet
CVE-2021-32608
+1 in the same advisory: …32607
An issue was discovered in Smartstore (aka SmartStoreNET) through 4.1.1.

An issue was discovered in Smartstore (aka SmartStoreNET) through 4.1.1. Views/Boards/Partials/_ForumPost.cshtml does not call HtmlUtils.SanitizeHtml on certain text for a forum post.

NVD description · AI analysis pending
9.833% PoC
  • smartstore smartstore
CVE-2020-27997
An issue was discovered in SmartStoreNET before 4.1.0.

An issue was discovered in SmartStoreNET before 4.1.0. Lack of Cross Site Request Forgery (CSRF) protection may lead to elevation of privileges (e.g., /admin/customer/create to create an admin account).

NVD description · AI analysis pending
8.8<1% PoC
  • smartstore smartstorenet
CVE-2020-27996
An issue was discovered in SmartStoreNET before 4.0.1.

An issue was discovered in SmartStoreNET before 4.0.1. It does not properly consider the need for a CustomModelPartAttribute decoration in certain ModelBase.CustomProperties situations.

NVD description · AI analysis pending
8.82% PoC
  • smartstore smartstorenet
CVE-2020-15243
Affected versions of Smartstore have a missing WebApi Authentication attribute.

Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore shops in version 4.0.0 & 4.0.1 which have installed and activated the Web API plugin. Users of Smartstore 4.0.0 and 4.0.1 must merge their repository with 4.0.x or overwrite the file SmartStore.Web.Framework in the */bin* directory of the deployed shop with this file. As a workaround without updating uninstall the Web API plugin to close this vulnerability.

NVD description · AI analysis pending
9.81%
  • smartstore smartstore