CVE-2026-100879: zhistaredu StarTraining dataScope Endpoint SysRoleServiceImpl.java checkRoleAllowed authorization
A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. This affects the function checkRoleAllowed of the file SysRoleServiceImpl.java of the component dataScope Endpoint. The manipulation results in missing authorization. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vulnerability requires low-level privileges (PR:L). It is remotely exploitable, does not require user interaction, and has low attack complexity.
Which versions are known to be affected?
zhistaredu StarTraining versions up to and including 3.8.1 are identified as affected. No fixed version is provided in the available information.
What is the likely impact of successful exploitation?
Successful exploitation can result in missing authorization and unauthorized modification of data or functionality. The provided vector indicates low integrity impact, with no stated confidentiality or availability impact.
Is exploit code available?
Yes. The exploit has been publicly released and may be used in attacks.