{"id":"CVE-2020-36364","details":"An issue was discovered in Smartstore (aka SmartStoreNET) before 4.1.0. Administration/Controllers/ImportController.cs allows path traversal (for copy and delete actions) in the ImportController.Create method via a TempFileName field.","modified":"2026-07-08T20:29:28.669376Z","published":"2021-05-19T19:15:08.267Z","references":[{"type":"REPORT","url":"https://github.com/smartstore/SmartStoreNET/issues/2112"},{"type":"FIX","url":"https://github.com/smartstore/SmartStoreNET/commit/5ab1e37dc8d6415d04354e1a116f3d82e9555f5c"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/smartstore/smartstorenet","events":[{"introduced":"0"},{"fixed":"b1f535a0409de6e6dec96619f3d9180b686e3a70"},{"fixed":"5ab1e37dc8d6415d04354e1a116f3d82e9555f5c"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:smartstore:smartstorenet:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"4.1.0"}]}}],"versions":["4.0.0","3.2.1","3.2.0","3.1.5","3.1.0","3.0.2","3.0.1","3.0.0","2.5.0","2.2.1","2.2.0","2.1.1","2.0.1","1.2.1","1.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-36364.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"}]}