CVE-2020-36926: SmarterTools SmarterTrack 7922 -Information Disclosure
SmarterTrack 7922 contains an information disclosure vulnerability in the Chat Management search form that reveals agent identification details. Attackers can access the vulnerable /Management/Chat/frmChatSearch.aspx endpoint to retrieve agents' first and last names along with their unique identifiers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36926?
CVE-2020-36926 is classified as a medium severity vulnerability due to the potential for information disclosure.
How do I fix CVE-2020-36926?
To mitigate CVE-2020-36926, upgrade to the latest version of SmarterTools SmarterTrack that addresses this vulnerability.
What type of vulnerability is CVE-2020-36926?
CVE-2020-36926 is an information disclosure vulnerability affecting the Chat Management component of SmarterTrack.
What details can be leaked by CVE-2020-36926?
CVE-2020-36926 allows unauthorized access to agent identification details through a vulnerable endpoint.
Is CVE-2020-36926 easy to exploit?
Exploitation of CVE-2020-36926 may be straightforward for attackers familiar with the affected endpoint and its functionality.