在 zhistaredu StarTraining 3.8.1 及更早版本中发现了一个安全弱点。该漏洞影响组件“上传端点”中文件 的未知代码部分。该问题源于对参数 File 的错误处理,可导致跨站脚本攻击(XSS)。攻击者可远程发起此类攻击。相关利用代码已公开,可能被用于实施攻击。早在漏洞披露初期即已联系厂商,但未收到任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zhistaredu | StarTraining | 3.8.0 |
cpe:2.3:a:zhistaredu:startraining:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100878 | 6.3 MEDIUM | zhistaredu StarTraining authRole Endpoint SysUser.java SysUser.isAdmin authorization |
| CVE-2026-100879 | 4.3 MEDIUM | zhistaredu StarTraining dataScope Endpoint SysRoleServiceImpl.java checkRoleAllowed author |
| CVE-2026-100881 | 2.6 LOW | zhistaredu StarTraining application.yml cross site scripting |
No comments yet