Marcus Gesing

2 exploits Active since May 2021
CVE-2020-36364 WRITEUP CRITICAL WRITEUP
Smartstorenet < 4.1.0 - Path Traversal
An issue was discovered in Smartstore (aka SmartStoreNET) before 4.1.0. Administration/Controllers/ImportController.cs allows path traversal (for copy and delete actions) in the ImportController.Create method via a TempFileName field.
CVSS 9.1
CVE-2021-32607 WRITEUP CRITICAL WRITEUP
Smartstore <4.1.1 - XSS
An issue was discovered in Smartstore (aka SmartStoreNET) through 4.1.1. Views/PrivateMessages/View.cshtml does not call HtmlUtils.SanitizeHtml on a private message.
CVSS 9.8