CVE-2026-3720

LOW

1024-lab/lab1024 SmartAdmin <3.29 - XSS

Title source: llm
STIX 2.1

Description

A security flaw has been discovered in 1024-lab/lab1024 SmartAdmin up to 3.29. Impacted is an unknown function of the file smart-admin-web-javascript/src/views/business/oa/notice/components/notice-form-drawer.vue of the component Notice Module. The manipulation results in cross site scripting. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Permissions Required, VDB Entry vdb-entry
https://vuldb.com/?id.349663
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.349663
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.765890

Scores

CVSS v3 3.5
EPSS 0.0022
EPSS Percentile 12.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79 CWE-94
Status published
Products (1)
lab1024/smartadmin < 3.29
Published Mar 08, 2026
Tracked Since Mar 08, 2026