Impact
A weakness in SmartAdmin’s HelpDocAddForm component enables malicious script injection. The vulnerability is triggered when an attacker crafts input that is rendered in the Help Documentation module, causing browsers of users who view the page to execute the injected code. This can lead to theft of session data, defacement, or further exploitation within the user’s context.
Affected Systems
SmartAdmin versions up to 3.29 from both 1024‑lab and lab1024 are affected. Any installation that includes the Help Documentation module in these releases is vulnerable.
Risk and Exploitability
The CVSS score of 5.1 denotes moderate severity, while the EPSS score of less than 1% indicates a low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Attackers can potentially deliver the payload remotely by sending crafted requests that influence the HelpDocAddForm endpoint, after which legitimate users will become victims when they access the compromised documentation.
OpenCVE Enrichment