CVE-2020-36926

7.5

SmarterTools · SmarterTrack

SmarterTools SmarterTrack contains an information disclosure vulnerability in the Chat Management search form that allows unauthenticated access to sensitive agent identification data.

Executive summary

An unauthenticated information disclosure vulnerability in SmarterTools SmarterTrack allows remote attackers to harvest sensitive agent identification details via a public-facing endpoint.

Vulnerability

The application is susceptible to an information disclosure flaw via the /Management/Chat/frmChatSearch.aspx endpoint. An unauthenticated attacker can query this endpoint to retrieve agent first names, last names, and unique internal identifiers.

Business impact

The exposure of internal agent names and unique identifiers facilitates targeted social engineering, phishing, or brute-force attacks against organizational support staff. While the CVSS score of 7.5 indicates a high-severity risk, the primary impact is the loss of internal system intelligence, which significantly lowers the barrier for subsequent, more destructive attacks against the infrastructure.

Remediation

Immediate Action: Organizations should review the SmarterTools advisory for the latest security patches and apply them to all affected SmarterTrack instances immediately.

Proactive Monitoring: Security teams should monitor web server access logs for anomalous or high-frequency requests directed at /Management/Chat/frmChatSearch.aspx.

Compensating Controls: Implement a Web Application Firewall (WAF) rule to block or restrict access to the /Management/Chat/frmChatSearch.aspx endpoint to unauthorized external IP addresses.

Exploitation status

Public Exploit Available: Yes, a proof-of-concept exploit is available via ExploitDB (EDB-ID 50328).

Analyst recommendation

This vulnerability presents a clear risk to operational security by exposing internal personnel data. Administrators must prioritize patching or restricting access to the affected endpoint to prevent unauthorized information gathering. Given the availability of exploit code, immediate remediation is strongly advised to maintain the integrity of internal user lists.

More SmarterTools CVEs

Sources

Originally found and disclosed by Andrei Manole, per the CVE Program record.