Lucene search

K
osvGoogleOSV:CVE-2020-27997
HistoryFeb 19, 2021 - 11:15 p.m.

CVE-2020-27997

2021-02-1923:15:12
Google
osv.dev
3
smartstorenet
csrf protection
privilege elevation
admin account creation

AI Score

7

Confidence

Low

EPSS

0.001

Percentile

44.3%

An issue was discovered in SmartStoreNET before 4.1.0. Lack of Cross Site Request Forgery (CSRF) protection may lead to elevation of privileges (e.g., /admin/customer/create to create an admin account).

AI Score

7

Confidence

Low

EPSS

0.001

Percentile

44.3%

Related for OSV:CVE-2020-27997