CVE-2020-27997

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
19/02/2021
Last modified:
21/07/2021

Description

An issue was discovered in SmartStoreNET before 4.1.0. Lack of Cross Site Request Forgery (CSRF) protection may lead to elevation of privileges (e.g., /admin/customer/create to create an admin account).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:smartstore:smartstorenet:*:*:*:*:*:*:*:* 4.1.0 (excluding)