CVE-2026-2972

LOW

Smart-SSO < 2.1.1 - Stored Cross-Site Scripting in Role Edit Page

Title source: llm
STIX 2.1

Description

A vulnerability was determined in a466350665 Smart-SSO up to 2.1.1. This affects the function Save of the file smart-sso-server/src/main/java/openjoe/smart/sso/server/controller/admin/UserController.java of the component Role Edit Page. Executing a manipulation can lead to cross site scripting. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.347339
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.347339
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.756026

Scores

CVSS v3 2.4
EPSS 0.0026
EPSS Percentile 17.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79 CWE-94
Status published
Products (1)
a466350665/smart-sso < 2.1.1
Published Feb 23, 2026
Tracked Since Feb 23, 2026