Vulnerability Description
Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore shops in version 4.0.0 & 4.0.1 which have installed and activated the Web API plugin. Users of Smartstore 4.0.0 and 4.0.1 must merge their repository with 4.0.x or overwrite the file SmartStore.Web.Framework in the */bin* directory of the deployed shop with this file. As a workaround without updating uninstall the Web API plugin to close this vulnerability.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Smartstore | Smartstore | 4.0.0 |
Related Weaknesses (CWE)
References
- https://github.com/smartstore/SmartStoreNET/security/advisories/GHSA-8g9m-jx26-qThird Party Advisory
- https://github.com/smartstore/SmartStoreNET/security/advisories/GHSA-8g9m-jx26-qThird Party Advisory
FAQ
What is CVE-2020-15243?
CVE-2020-15243 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore shops in version 4.0.0 & 4.0.1 which have installed and activated the Web API plug...
How severe is CVE-2020-15243?
CVE-2020-15243 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-15243?
Check the references section above for vendor advisories and patch information. Affected products include: Smartstore Smartstore.