← Back

Smartertrack

smartertrack

Vendor: Smartertools • 7 CVEs

CVEs (7)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Smartertools
1Smartertrack
Jun 17, 2026
Jan 16, 2026
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
SmarterTrack 7922 contains an information disclosure vulnerability in the Chat Management search form that reveals agent identification details. Attackers can access the vulnerable /Management/Chat/frmChatSearch.aspx end...Show more
SmarterTrack 7922 contains an information disclosure vulnerability in the Chat Management search form that reveals agent identification details. Attackers can access the vulnerable /Management/Chat/frmChatSearch.aspx endpoint to retrieve agents' first and last names along with their unique identifiers.Show less
1Smartertools
1Smartertrack
Jun 17, 2026
Mar 14, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
With administrator or admin privileges the application can be tricked into overwriting files in app_data/Config folder, e.g. the systemsettings.xml file. THis is possible in SmarterTrack v100.0.8019.14010
1Smartertools
1Smartertrack
Jun 17, 2026
Mar 14, 2022
N/A· v4
6.1 MEDIUM· v3
3.5 LOW· v2
Stored XSS in SmarterTools SmarterTrack This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.
1Smartertools
1Smartertrack
Jun 17, 2026
Mar 14, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A Direct Object Access vulnerability in SmarterTools SmarterTrack leads to information disclosure This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.
1Smartertools
1Smartertrack
Jun 17, 2026
Mar 14, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site Scripting (XSS) vulnerability in SmarterTools SmarterTrack This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.
1Smartertools
1Smartertrack
Apr 29, 2026
Aug 25, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in frmTickets.aspx in SmarterTools SmarterTrack before 4.0.3504 allows remote attackers to inject arbitrary web script or HTML via the email address field. NOTE: the provenance o...Show more
Cross-site scripting (XSS) vulnerability in frmTickets.aspx in SmarterTools SmarterTrack before 4.0.3504 allows remote attackers to inject arbitrary web script or HTML via the email address field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Smartertools
1Smartertrack
Apr 29, 2026
Aug 25, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in frmKBSearch.aspx in SmarterTools SmarterTrack before 4.0.3504 allows remote attackers to inject arbitrary web script or HTML via the search parameter.