Impact
SmartAdmin version 3.30.0 contains an authorization flaw in its configuration query endpoint. The flaw allows a remote attacker who can reach that endpoint to bypass built‑in authorization checks and gain elevated privileges. By exploiting this weakness, the attacker can read or alter critical configuration data, potentially creating a foothold for further malicious operations. This vulnerability is an example of improper access control and a failure to enforce proper authorization on public endpoints (CWE‑863).
Affected Systems
The affected product is SmartAdmin 3.30.0, specifically the configuration query API endpoint. No other version ranges are indicated in the CNA data, so any installation identified as running 3.30.0 should verify its version and consider upgrading if a fix is released.
Risk and Exploitability
The vulnerability has a CVSS score of 9.8, indicating a high severity of remote privilege escalation. The EPSS score is below 1 %, suggesting a low likelihood of exploitation, but not impossible, especially if the endpoint is publicly reachable. Based on the description, it is inferred that the flaw may be exploitable by any remote user who can reach the configuration endpoint, although the CVE does not explicitly state whether authentication is required. The issue is not listed in CISA’s KEV catalog, but due to its severe impact it remains a priority for immediate remediation.
OpenCVE Enrichment