Lucene search

K
cvelistMitreCVELIST:CVE-2020-27997
HistoryFeb 19, 2021 - 11:00 p.m.

CVE-2020-27997

2021-02-1923:00:25
mitre
www.cve.org
3
smartstorenet
csrf protection
privilege elevation
admin account

AI Score

8.9

Confidence

High

EPSS

0.001

Percentile

44.3%

An issue was discovered in SmartStoreNET before 4.1.0. Lack of Cross Site Request Forgery (CSRF) protection may lead to elevation of privileges (e.g., /admin/customer/create to create an admin account).

AI Score

8.9

Confidence

High

EPSS

0.001

Percentile

44.3%

Related for CVELIST:CVE-2020-27997