CVE-2020-36364

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
19/05/2021
Last modified:
25/05/2021

Description

An issue was discovered in Smartstore (aka SmartStoreNET) before 4.1.0. Administration/Controllers/ImportController.cs allows path traversal (for copy and delete actions) in the ImportController.Create method via a TempFileName field.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:smartstore:smartstorenet:*:*:*:*:*:*:*:* 4.1.0 (excluding)