CVE-2026-2972

A

vulnerability was determined in a466350665 Smart-SSO up to 2.1.1. This affects the function Save of the file smart-sso-server/src/main/java/openjoe/smart/sso/server/controller/admin/UserController.java of the component Role Edit Page. Executing a manipulation can lead to cross site scripting. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

References
Link Resource
https://vuldb.com/?ctiid.347339 Permissions Required VDB Entry
https://vuldb.com/?id.347339 Third Party Advisory VDB Entry
https://vuldb.com/?submit.756026 Third Party Advisory VDB Entry
https://www.notion.so/Smart-SSO-Stored-Cross-Site-Scripting-XSS-in-Role-Edit-Page-303ea92a3c4180f4beb9c119653ce51d Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:a466350665:smart-sso:*:*:*:*:*:*:*:*

History

25 Feb 2026, 15:11

Type Values Removed Values Added
First Time A466350665 smart-sso
A466350665
CPE cpe:2.3:a:a466350665:smart-sso:*:*:*:*:*:*:*:*
References () https://vuldb.com/?ctiid.347339 - () https://vuldb.com/?ctiid.347339 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.347339 - () https://vuldb.com/?id.347339 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.756026 - () https://vuldb.com/?submit.756026 - Third Party Advisory, VDB Entry
References () https://www.notion.so/Smart-SSO-Stored-Cross-Site-Scripting-XSS-in-Role-Edit-Page-303ea92a3c4180f4beb9c119653ce51d - () https://www.notion.so/Smart-SSO-Stored-Cross-Site-Scripting-XSS-in-Role-Edit-Page-303ea92a3c4180f4beb9c119653ce51d - Exploit, Third Party Advisory

23 Feb 2026, 18:13

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-23 06:16

Updated : 2026-02-25 15:11


NVD link : CVE-2026-2972

Mitre link : CVE-2026-2972

CVE.ORG link : CVE-2026-2972


JSON object : View

Products Affected
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')