CVE-2026-88618: 1024-lab SmartAdmin vulnerability
Published Sep 15, 2026
·Updated
1024-lab SmartAdmin v3.30.0 contains a stored cross-site scripting vulnerability in its file upload functionality. This allows a remote attacker to execute arbitrary code.
Affected Software
1 affected component
1024-lab SmartAdmin=3.30.0
Event History
Sep 15, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The available information identifies the issue as a stored cross-site scripting flaw in file upload functionality, but does not state whether authentication or upload permissions are required.
2
Which releases are identified as affected?
The reported affected release is 1024-lab SmartAdmin v3.30.0.
3
What is the likely impact after exploitation?
The report states that a remote attacker can execute arbitrary code through the stored cross-site scripting vulnerability.