CVE-2026-100881: zhistaredu StarTraining application.yml cross site scripting
A security vulnerability has been detected in zhistaredu StarTraining up to 3.8.1. This issue affects some unknown processing of the file application.yml. Such manipulation of the argument xss.enabled leads to cross site scripting. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit has been disclosed publicly and may be used. Not independently exploitable: a defense-in-depth absence that amplifies CVE-2026-100880. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Can this issue be exploited on its own?
No. It is described as a defense-in-depth absence that amplifies CVE-2026-100880 and is not independently exploitable.
What access and conditions does an attacker need?
The attack can be launched remotely, but it requires low privileges and user interaction. Exploitation is assessed as highly complex and difficult.
Which deployments should be prioritized for review?
Review zhistaredu StarTraining deployments up to version 3.8.1, particularly where an attacker could manipulate the xss.enabled argument in application.yml. The available information does not state whether the default configuration is affected.