Impact
A stored cross-site scripting flaw exists in the Role Edit page of the Smart-SSO application. The vulnerability resides in the save action of UserController.java, enabling an attacker to inject malicious scripts that execute in the browsers of users who view the role edit page. Because the script is stored, it can be reused against multiple users, potentially compromising session tokens, defacing the UI, or redirecting traffic.
Affected Systems
The issue affects all deployed versions of Smart-SSO up to and including 2.1.1. Attackers need only submit crafted input through the role management interface, and any authenticated or unauthenticated user who accesses the edited role will receive the injected script. The vendor identifier a466350665 is associated with this product.
Risk and Exploitability
The CVSS v3.1 score of 4.8 indicates moderate severity, while the EPSS percentage below 1% suggests a low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, reducing immediate red flag status. Nonetheless, because exploitation can happen remotely by manipulating a role edit request, the risk to organizations running affected versions remains significant.
OpenCVE Enrichment