CVE-2020-36926

SmarterTrack 7922 contains an information disclosure vulnerability in the Chat Management search form that reveals agent identification details. Attackers can access the vulnerable /Management/Chat/frmChatSearch.aspx endpoint to retrieve agents' first and last names along with their unique identifiers.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:smartertools:smartertrack:10.0:*:*:*:*:*:*:*
cpe:2.3:a:smartertools:smartertrack:14.0:*:*:*:*:*:*:*

History

17 Jun 2026, 03:16

Type Values Removed Values Added
Summary
  • (es) SmarterTrack 7922 contiene una vulnerabilidad de revelación de información en el formulario de búsqueda de Gestión de Chat que revela detalles de identificación de agentes. Los atacantes pueden acceder al endpoint vulnerable /Management/Chat/frmChatSearch.aspx para recuperar los nombres y apellidos de los agentes junto con sus identificadores únicos.

09 Feb 2026, 15:12

Type Values Removed Values Added
CPE cpe:2.3:a:smartertools:smartertrack:10.0:*:*:*:*:*:*:*
cpe:2.3:a:smartertools:smartertrack:14.0:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
References () https://www.exploit-db.com/exploits/50328 - () https://www.exploit-db.com/exploits/50328 - Exploit
References () https://www.smartertools.com/ - () https://www.smartertools.com/ - Product
References () https://www.smartertools.com/smartertrack - () https://www.smartertools.com/smartertrack - Product
References () https://www.vulncheck.com/advisories/smartertools-smartertrack-information-disclosure - () https://www.vulncheck.com/advisories/smartertools-smartertrack-information-disclosure - Third Party Advisory
First Time Smartertools smartertrack
Smartertools

20 Jan 2026, 17:15

Type Values Removed Values Added
References () https://www.exploit-db.com/exploits/50328 - () https://www.exploit-db.com/exploits/50328 -

16 Jan 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-16 00:16

Updated : 2026-06-17 03:16


NVD link : CVE-2020-36926

Mitre link : CVE-2020-36926

CVE.ORG link : CVE-2020-36926


JSON object : View

Products Affected

smartertools

  • smartertrack
CWE
CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere

NVD-CWE-noinfo