CVE-2020-36926: SmarterTools Smartertrack

Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.

SmarterTrack 7922 contains an information disclosure vulnerability in the Chat Management search form that reveals agent identification details. Attackers can access the vulnerable /Management/Chat/frmChatSearch.aspx endpoint to retrieve agents' first and last names along with their unique identifiers.

Affected products

  • SmarterTools Smartertrack: version 10.0 only; version 14.0 only

Published 2026-01-16. Last modified 2026-06-17.