CVE-2026-2972

A vulnerability was determined in a466350665 Smart-SSO up to 2.1.1. This affects the function Save of the file smart-sso-server/src/main/java/openjoe/smart/sso/server/controller/admin/UserController.java of the component Role Edit Page. Executing a manipulation can lead to cross site scripting. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://vuldb.com/?ctiid.347339 Permissions Required VDB Entry
https://vuldb.com/?id.347339 Third Party Advisory VDB Entry
https://vuldb.com/?submit.756026 Third Party Advisory VDB Entry
https://www.notion.so/Smart-SSO-Stored-Cross-Site-Scripting-XSS-in-Role-Edit-Page-303ea92a3c4180f4beb9c119653ce51d Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:a466350665:smart-sso:*:*:*:*:*:*:*:*

History

25 Feb 2026, 15:11

Type Values Removed Values Added
First Time A466350665
A466350665 smart-sso
CPE cpe:2.3:a:a466350665:smart-sso:*:*:*:*:*:*:*:*
References () https://vuldb.com/?ctiid.347339 - () https://vuldb.com/?ctiid.347339 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.347339 - () https://vuldb.com/?id.347339 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.756026 - () https://vuldb.com/?submit.756026 - Third Party Advisory, VDB Entry
References () https://www.notion.so/Smart-SSO-Stored-Cross-Site-Scripting-XSS-in-Role-Edit-Page-303ea92a3c4180f4beb9c119653ce51d - () https://www.notion.so/Smart-SSO-Stored-Cross-Site-Scripting-XSS-in-Role-Edit-Page-303ea92a3c4180f4beb9c119653ce51d - Exploit, Third Party Advisory

23 Feb 2026, 18:13

Type Values Removed Values Added
Summary
  • (es) Se ha encontrado una vulnerabilidad en a466350665 Smart-SSO hasta 2.1.1. Esta afecta a la función Save del archivo smart-sso-server/src/main/java/openjoe/smart/sso/server/controller/admin/UserController.java del componente 'Role Edit Page'. Ejecutar una manipulación puede provocar un cross-site scripting. El ataque puede realizarse de forma remota. El exploit ha sido divulgado públicamente y puede ser utilizado. El proveedor fue contactado con antelación sobre esta divulgación, pero no respondió de ninguna manera.

23 Feb 2026, 06:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-23 06:16

Updated : 2026-02-25 15:11


NVD link : CVE-2026-2972

Mitre link : CVE-2026-2972

CVE.ORG link : CVE-2026-2972


JSON object : View

Products Affected

a466350665

  • smart-sso
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')