VYPR
Critical severity9.1NVD Advisory· Published Oct 8, 2020· Updated Jun 17, 2026

CVE-2020-15243

CVE-2020-15243

Description

Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore shops in version 4.0.0 & 4.0.1 which have installed and activated the Web API plugin. Users of Smartstore 4.0.0 and 4.0.1 must merge their repository with 4.0.x or overwrite the file SmartStore.Web.Framework in the */bin* directory of the deployed shop with this file. As a workaround without updating uninstall the Web API plugin to close this vulnerability.

Affected products

4
  • cpe:2.3:a:smartstore:smartstore:4.0.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:smartstore:smartstore:4.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:smartstore:smartstore:4.0.1:*:*:*:*:*:*:*
  • Range: 4.0.0, 4.0.1
  • smartstore/SmartStoreNETv5
    Range: >= 4.0.0, <= 4.0.1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.