Impact
The vulnerability lies in the AdminSmartJobController of 1024‑lab SmartAdmin v3.30.0. The controller exposes scheduled‑job management endpoints without method‑level permission checks, allowing a user with only basic authenticated access to perform actions that should be restricted to administrators. This defect can lead to unauthorized creation, modification, or deletion of scheduled jobs, compromising the integrity of automated tasks and potentially enabling further scheduled jobs to run scripts. The weakness matches CWE‑862, which highlights missing authorization controls.
Affected Systems
The affected product is 1024‑lab SmartAdmin version 3.30.0; unless a compatible patch or configuration change is applied, these installations remain impacted.
Risk and Exploitability
The CVSS score of 8.1 categorises this flaw as available, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score of < 1% indicates a very low exploitation probability. Based on the description, the attack vector requires a low‑privileged authenticated user who can reach the AdminSmartJobController endpoints. Thus the risk is significant for environments where all authenticated users have network access to the application and the endpoint is exposed without further network restrictions. No public exploit for this specific vulnerability has been reported at the time of this analysis.
OpenCVE Enrichment