Description
A vulnerability was found in a466350665 Smart-SSO up to 2.1.1. Affected by this issue is some unknown functionality of the file smart-sso-server/src/main/resources/templates/login.html of the component Login. Performing a manipulation of the argument redirectUri results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-02-23
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting (Remote)
Action: Assess
AI Analysis

Impact

A recently disclosed flaw in the Smart‑SSO login interface allows crafted input to the redirectUri parameter to inject unescaped script payloads into login.html, enabling a classic cross‑site scripting attack. The vulnerability can be triggered from a remote location without any local privilege, allowing an attacker to execute arbitrary JavaScript in the context of the user’s browser. This could lead to session hijacking, credential theft, or execution of malicious actions on behalf of the victim.

Affected Systems

The flaw affects the Smart‑SSO product developed by a466350665, specifically all instances up to and including version 2.1.1. Administrators should verify whether their environment runs any of these affected releases.

Risk and Exploitability

The CVSS base score of 5.3 indicates a moderate severity. Current EPSS data shows a likelihood of exploitation in the <1% range, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited current public exploitation activity. Nonetheless, because the attack vector is remote and the payload can be crafted through a standard HTTP parameter, the risk of a successful exploit remains real until a vendor‑issued fix or effective mitigation is applied. Executing the redirectUri manipulation can be accomplished via a simple crafted URL, making the vulnerability readily exploitable in typical web‑based scenarios.

Generated by OpenCVE AI on April 18, 2026 at 11:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Validate and sanitize all user‑supplied values for redirectUri to ensure that no script tags or dangerous payloads are rendered in the login template.
  • Implement output‑escaping mechanisms provided by your web framework rather than manually inserting the parameter.
  • If the redirect capability is not required, disable or remove the redirectUri parameter entirely.
  • Regularly check the vendor’s website for an updated release that addresses the issue and apply that fix as soon as it becomes available.

Generated by OpenCVE AI on April 18, 2026 at 11:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 25 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:a466350665:smart-sso:*:*:*:*:*:*:*:*

Mon, 23 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared A466350665
A466350665 smart-sso
Vendors & Products A466350665
A466350665 smart-sso

Mon, 23 Feb 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 23 Feb 2026 05:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in a466350665 Smart-SSO up to 2.1.1. Affected by this issue is some unknown functionality of the file smart-sso-server/src/main/resources/templates/login.html of the component Login. Performing a manipulation of the argument redirectUri results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title a466350665 Smart-SSO Login login.html cross site scripting
Weaknesses CWE-79
CWE-94
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

A466350665 Smart-sso
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T13:59:00.367Z

Reserved: 2026-02-22T08:16:22.824Z

Link: CVE-2026-2971

cve-icon Vulnrichment

Updated: 2026-02-23T13:58:53.852Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-23T05:16:20.663

Modified: 2026-04-29T01:00:01.613

Link: CVE-2026-2971

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T11:15:35Z

Weaknesses