在 zhistaredu StarTraining 3.8.1 及更早版本中发现了一个安全漏洞。受影响的元素是 api-docs 组件中 SecurityConfig.java 文件的一个未知函数。该漏洞可能导致认证缺失,从而允许攻击者绕过身份验证机制。此漏洞可被远程利用,且相关利用代码已公开,可能被用于实施攻击。供应商在披露初期已被联系,但未作任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zhistaredu | StarTraining | 3.8.0 |
cpe:2.3:a:zhistaredu:startraining:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-97877 | 7.3 HIGH | zhistaredu StarTraining JWT Token application.yml UserLoginService.createToken hard-coded |
| CVE-2026-97878 | 7.3 HIGH | zhistaredu StarTraining Druid Console index.html anonymous missing authentication |
No comments yet