在 zhistaredu StarTraining 3.8.1 及更早版本中发现了一个漏洞。该漏洞影响位于组件 authRole Endpoint 中的文件 edu-common/src/main/java/com/edu/common/core/domain/entity/SysUser.java 的 SysUser.isAdmin 函数。对用户 ID(userId)/角色 ID(roleIds)参数的操纵会导致授权绕过。该漏洞可被远程利用,并且相关漏洞利用代码已公开,可能被恶意利用。尽管厂商在披露初期已被联系,
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zhistaredu | StarTraining | 3.8.0 |
cpe:2.3:a:zhistaredu:startraining:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100879 | 4.3 MEDIUM | zhistaredu StarTraining dataScope Endpoint SysRoleServiceImpl.java checkRoleAllowed author |
| CVE-2026-100880 | 3.5 LOW | zhistaredu StarTraining Upload Endpoint MimeTypeUtils.java cross site scripting |
| CVE-2026-100881 | 2.6 LOW | zhistaredu StarTraining application.yml cross site scripting |
No comments yet