Lucene search

K
osvGoogleOSV:CVE-2020-15243
HistoryOct 08, 2020 - 11:15 p.m.

CVE-2020-15243

2020-10-0823:15:10
Google
osv.dev
5
smartstore
version 4.0.x
web api plugin

AI Score

6.8

Confidence

High

EPSS

0.003

Percentile

70.1%

Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore shops in version 4.0.0 & 4.0.1 which have installed and activated the Web API plugin. Users of Smartstore 4.0.0 and 4.0.1 must merge their repository with 4.0.x or overwrite the file SmartStore.Web.Framework in the /bin directory of the deployed shop with this file. As a workaround without updating uninstall the Web API plugin to close this vulnerability.

AI Score

6.8

Confidence

High

EPSS

0.003

Percentile

70.1%

Related for OSV:CVE-2020-15243