在 zhistaredu StarTraining 3.8.1 及之前版本中发现了一个漏洞。该问题影响 JWT Token Handler 组件中的 文件的 函数。此对用户 ID/公司 ID 参数的操纵导致使用了硬编码密码。该攻击可远程执行。漏洞利用代码已公开披露,且可能被实际利用。厂商在披露前已被联系,但未作任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zhistaredu | StarTraining | 3.8.0 |
cpe:2.3:a:zhistaredu:startraining:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-97878 | 7.3 HIGH | zhistaredu StarTraining Druid Console index.html anonymous missing authentication |
| CVE-2026-97879 | 5.3 MEDIUM | zhistaredu StarTraining api-docs Endpoint SecurityConfig.java missing authentication |
No comments yet