Sceawere

Vulnerability Detail

CVE-2026-100881UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

StarTraining XSS via application.yml

Vulnerability Metadata

Severity
Low
Score / CVSS
2.6
Creation Date
10h ago
Vendor
zhistaredu
Product
StarTraining
Attack Type
Cross Site Scripting
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

A security vulnerability has been detected in zhistaredu StarTraining up to 3.8.1. This issue affects some unknown processing of the file application.yml. Such manipulation of the argument xss.enabled leads to cross site scripting. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit has been disclosed publicly and may be used. Not independently exploitable: a defense-in-depth absence that amplifies CVE-2026-100880. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "2.6",
  "pubDate": "2026-09-27T22:17:05.047Z",
  "pubdate": "2026-09-27T22:17:05.047Z",
  "executiveSummary": "A Cross-Site Scripting (XSS) vulnerability exists in zhistaredu StarTraining versions up to 3.8.1, identified under CVE-2026-100880.\nThe vulnerability originates from improper handling of the xss.enabled configuration parameter within the application.yml file, allowing for the injection of malicious scripts into the web application context.\nThis flaw is remotely exploitable, though it is categorized as highly complex and difficult to execute. The vulnerability serves as a critical defense-in-depth failure, potentially amplifying the impact of other security weaknesses.\nThe vulnerability is currently public, and there is no evidence of a vendor-provided fix or response. Unauthorized attackers can leverage this issue to execute arbitrary scripts in the victim's browser session, leading to potential session hijacking, data exfiltration, or unauthorized actions performed on behalf of authenticated users.\nDue to the nature of the vulnerability and the absence of a vendor patch, organizations are advised to implement immediate compensating controls to restrict unauthorized configuration access.",
  "technicalDetails": "The vulnerability resides in the configuration processing logic of the zhistaredu StarTraining framework (versions <= 3.8.1). Specifically, the application parses the application.yml file to determine security posture, including the status of XSS filtering via the xss.enabled argument.\nThe root cause is a failure in the application's sanitization routine or internal logic flow, which incorrectly processes the xss.enabled flag. When manipulated, this configuration allows an attacker to bypass intended security controls that should otherwise mitigate XSS vectors.\nExploitation is achieved by targeting the processing layer of the application.yml configuration. Because the application fails to properly validate the input or state associated with the xss.enabled argument, an attacker can supply crafted payloads that the application executes within the context of the end-user's browser. The exploitability is deemed 'difficult' due to the requirements for specific environmental conditions or the necessity of chaining this flaw with other secondary vulnerabilities or misconfigurations.\nThe attack flow follows a remote exploitation pattern where an attacker identifies the target interface that reflects the state controlled by the application.yml file. Upon crafting a malicious payload that bypasses the improperly configured security filter, the attacker induces a victim to interact with the compromised endpoint. The payload is then reflected back to the user, executing arbitrary JavaScript. This effectively circumvents the defense-in-depth mechanisms that are otherwise expected to maintain site integrity.\nThe impact post-exploitation includes the potential for session token theft, unauthorized modification of the Document Object Model (DOM) to spoof content, and the initiation of unwanted requests initiated from the user's origin. The vulnerability remains critical as it allows for persistent or reflected XSS depending on how the application reflects the configured settings. Since no vendor patch exists for this specific disclosure, the application remains susceptible to remote attackers capable of influencing the server-side configuration environment."
}
CVE-2026-100881: StarTraining XSS via application.yml (LOW Severity, CVSS: 2.6) | Sceawere