{"id":"CVE-2021-32608","details":"An issue was discovered in Smartstore (aka SmartStoreNET) through 4.1.1. Views/Boards/Partials/_ForumPost.cshtml does not call HtmlUtils.SanitizeHtml on certain text for a forum post.","modified":"2026-05-16T04:03:05.618636682Z","published":"2021-05-12T15:15:07.743Z","database_specific":{},"references":[{"type":"FIX","url":"https://github.com/smartstore/SmartStoreNET/commit/ae03d45e23734555a2aef0b0c3d33c21e076c20f"},{"type":"EVIDENCE","url":"https://blog.sonarsource.com/smartstorenet-malicious-message-leading-to-e-commerce-takeover/"}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}