CVE-2023-37287: Smartsoft Smartbpm.net
Critical severity, CVSS 9.1. EPSS: 0.9% chance of exploitation in the next 30 days.
SmartBPM.NET has a vulnerability of using hard-coded authentication key. An unauthenticated remote attacker can exploit this vulnerability to access system with regular user privilege to read application data, and execute submission and approval processes.
Affected products
- Smartsoft Smartbpm.net: version 6.70 only
Published 2023-07-10. Last modified 2026-06-17.