Impact
A recently disclosed flaw in the Smart‑SSO login interface allows crafted input to the redirectUri parameter to inject unescaped script payloads into login.html, enabling a classic cross‑site scripting attack. The vulnerability can be triggered from a remote location without any local privilege, allowing an attacker to execute arbitrary JavaScript in the context of the user’s browser. This could lead to session hijacking, credential theft, or execution of malicious actions on behalf of the victim.
Affected Systems
The flaw affects the Smart‑SSO product developed by a466350665, specifically all instances up to and including version 2.1.1. Administrators should verify whether their environment runs any of these affected releases.
Risk and Exploitability
The CVSS base score of 5.3 indicates a moderate severity. Current EPSS data shows a likelihood of exploitation in the <1% range, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited current public exploitation activity. Nonetheless, because the attack vector is remote and the payload can be crafted through a standard HTTP parameter, the risk of a successful exploit remains real until a vendor‑issued fix or effective mitigation is applied. Executing the redirectUri manipulation can be accomplished via a simple crafted URL, making the vulnerability readily exploitable in typical web‑based scenarios.
OpenCVE Enrichment