Impact
1024‑lab SmartAdmin version 3.30.0 contains a stored cross‑site scripting vulnerability in its file upload feature that permits an attacker to execute arbitrary code in the browsers of users who view the uploaded content.
Affected Systems
The only effected product is 1024‑lab SmartAdmin 3.30.0; no other vendors or product versions are identified.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is less than 1%, reflecting a low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. The vulnerability can be exploited remotely by uploading a crafted file; the stored malicious content may later be leveraged by an attacker to execute arbitrary code.
OpenCVE Enrichment