PT-2021-12014 · Unknown · Smartstore

Eric-Therond-Sonarsource

·

Published

2021-05-19

·

Updated

2021-05-25

·

CVE-2020-36364

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Smartstore versions prior to 4.1.0
Description: An issue was discovered in the Administration/Controllers/ImportController.cs file, specifically in the ImportController.Create method, which allows path traversal for copy and delete actions via the TempFileName field.
Recommendations: For versions prior to 4.1.0, update to version 4.1.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the ImportController.Create method to minimize the risk of exploitation. Avoid using the TempFileName field in the affected method until the issue is resolved.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-36364

Affected Products

Smartstore