Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2020-15243 Details

Description

Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore shops in version 4.0.0 & 4.0.1 which have installed and activated the Web API plugin. Users of Smartstore 4.0.0 and 4.0.1 must merge their repository with 4.0.x or overwrite the file SmartStore.Web.Framework in the */bin* directory of the deployed shop with this file. As a workaround without updating uninstall the Web API plugin to close this vulnerability.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-306Missing Authentication for Critical Function[email protected]
CWE-287Improper Authentication[email protected]

Affected Products

ProductVersions
smartstore smartstore
4.0.0
4.0.1

CPE

  • cpe:2.3:a:smartstore:smartstore:4.0.0:*:*:*:*:*:*:*
  • cpe:2.3:a:smartstore:smartstore:4.0.1:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

5 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2020-15243
NVD Published Date:
Oct 8, 2020
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2020-15243 Details - Not Deferred