Intel

AIKIDO-2025-10295

Smartstore.Licensing is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

20

Low Risk

This Affects:

dotnetSmartstore.Licensing
5.0.0 - 6.0.0
Fixed in 6.1.0

TL;DR

Affected versions of the package are vulnerable to Cross-site Scripting (XSS). Older Smartstore.Licensing packages do not support strict-dynamic CSP (Content Security Policy), making them more susceptible to XSS attacks.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

Smartstore.Licensing is vulnerable to Cross-site Scripting (XSS) in versions 5.0.0 - 6.0.0.

How to fix this

Upgrade the Smartstore.Licensing library to the patch version.