S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2020-36365 Scanner

CVE-2020-36365 scanner - Open Redirect vulnerability in Smartstore (aka SmartStoreNET)

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-36365
6.1
CVSS

Smartstore (aka SmartStoreNET) before 4.1.0 allows CommonController.ClearCache, ClearDatabaseCache, RestartApplication, and ScheduleTaskController.Edit open redirect.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Smartstore (aka SmartStoreNET) is an open-source e-commerce platform developed on the .NET Core platform. This platform is used by businesses to create a digital storefront to sell their products and services. It provides a variety of features including, order management, inventory management, payment integration, and customer management. It is a popular choice for businesses that want to establish a digital presence and grow their online sales.

One of the vulnerabilities detected in Smartstore is CVE-2020-36365. This vulnerability, which affects Smartstore versions prior to 4.1.0, allows CommonController.ClearCache, ClearDatabaseCache, RestartApplication, and ScheduleTaskController.Edit open redirect. Essentially, this means that attackers can manipulate a URL to redirect users to a malicious website where they can be tricked into divulging sensitive information or installing malware.

If this vulnerability is exploited, it can lead to serious consequences for businesses. For example, hackers can use this vulnerability to steal credit card information, customer data, or even take full control of the targeted systems. Not only can businesses lose trust and reputation, but they may also face legal consequences and cost to fix the damage caused.

By subscribing to s4e.io, businesses can easily and quickly learn about vulnerabilities in their digital assets. s4e.io provides timely and detailed alerts on the latest vulnerabilities and security threats, as well as a comprehensive database of known security vulnerabilities across multiple platforms. With its pro features, businesses can protect their digital assets from malicious attacks and minimize the risk of data loss or breaches.

 

REFERENCES

Solution Advice

There are several precautions that businesses can take to protect themselves from this vulnerability. Some of these precautions include:

  • Updating to the latest version of Smartstore that includes a patch for this vulnerability
  • Implementing best practices for URL management to block open redirects
  • Enforcing strict access control policies to limit administrative access only to trusted personnel
  • Using firewall and intrusion detection systems to identify and block malicious traffic

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-36365 scanner - Open Redirect vulnerability in Smartstore (aka SmartStoreNET) | S4E