Sceawere

Vulnerability Detail

CVE-2026-100880UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

StarTraining XSS via File Upload

Vulnerability Metadata

Severity
Low
Score / CVSS
3.5
Creation Date
11h ago
Vendor
zhistaredu
Product
StarTraining
Attack Type
Cross Site Scripting
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

A weakness has been identified in zhistaredu StarTraining up to 3.8.1. This vulnerability affects unknown code of the file du-common/src/main/java/com/edu/common/utils/file/MimeTypeUtils.java of the component Upload Endpoint. This manipulation of the argument File causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.5",
  "pubDate": "2026-09-27T21:17:01.450Z",
  "pubdate": "2026-09-27T21:17:01.450Z",
  "executiveSummary": "A cross-site scripting (XSS) vulnerability exists within the zhistaredu StarTraining platform, affecting versions up to 3.8.1.\nThe vulnerability resides in the file upload endpoint, specifically within the MimeTypeUtils.java utility class, which fails to properly sanitize input provided through the file argument.\nThis flaw allows remote attackers to inject malicious scripts into the application, which are then executed in the context of the victim's browser session.\nThe impact includes the potential for session hijacking, unauthorized actions performed on behalf of the user, and theft of sensitive information.\nThe vulnerability is remotely exploitable, and a public exploit is available, significantly increasing the risk of successful exploitation.\nDespite early disclosure, the vendor has failed to provide a response or remediation for this security defect.",
  "technicalDetails": "The vulnerability is a reflected or stored cross-site scripting (XSS) flaw located in the component responsible for processing file uploads. The specific file affected is du-common/src/main/java/com/edu/common/utils/file/MimeTypeUtils.java.\nThe root cause of this vulnerability is the improper validation and sanitization of the file input processed by the application during the upload sequence. When a user submits a file, the application relies on the MimeTypeUtils utility to handle or process certain file-related parameters. Because this utility fails to adequately sanitize or encode the input, malicious JavaScript payloads can be embedded within the file metadata or the arguments passed during the upload request.\nThe attack flow begins when an attacker identifies the targeted upload endpoint. By crafting a request that includes a malicious payload within the file argument, the attacker can force the application to reflect this payload back to the browser. If the application environment improperly handles this input, the payload is rendered by the user's browser as active content.\nThe exploit can be initiated remotely, requiring no prior authentication depending on the exposure of the upload endpoint. Upon successful injection, the attacker's script executes within the security context of the victim's session on the StarTraining platform. This allows the attacker to bypass Same-Origin Policy (SOP) restrictions, access session cookies, perform unauthorized actions in the name of the logged-in user, or redirect users to malicious websites.\nSince the vulnerability exists in MimeTypeUtils.java, it suggests a systemic failure in input handling for file-related operations within the StarTraining framework. The absence of vendor-supplied patches means that the vulnerability remains active in all versions up to and including 3.8.1. Post-exploitation impact is severe, potentially leading to full account compromise if the victim possesses administrative privileges."
}
CVE-2026-100880: StarTraining XSS via File Upload (LOW Severity, CVSS: 3.5) | Sceawere