Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.3

Smart-SSO: Malicious Code Injection Through Login Page

CVE-2026-2971
Summary

A security flaw in Smart-SSO versions up to 2.1.1 allows attackers to inject malicious code into the login page, potentially allowing them to steal user data or take control of user sessions. This issue is particularly concerning because it can be exploited remotely. It's essential to update to the latest version of Smart-SSO to protect against this vulnerability.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
a466350665 smart-sso <= 2.1.1 –
Original title
A vulnerability was found in a466350665 Smart-SSO up to 2.1.1. Affected by this issue is some unknown functionality of the file smart-sso-server/src/main/resources/templates/login.html of the compo...
Original description
A vulnerability was found in a466350665 Smart-SSO up to 2.1.1. Affected by this issue is some unknown functionality of the file smart-sso-server/src/main/resources/templates/login.html of the component Login. Performing a manipulation of the argument redirectUri results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
nvd CVSS2.0 5.0
nvd CVSS3.1 6.1
nvd CVSS4.0 5.3
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
CWE-94 Code Injection
Published: 23 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026