Sceawere
Vulnerability Detail
CVE-2026-100881UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
StarTraining XSS via application.yml
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 2.6
- Creation Date
- 10h ago
- Vendor
- zhistaredu
- Product
- StarTraining
- Attack Type
- Cross Site Scripting
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
A security vulnerability has been detected in zhistaredu StarTraining up to 3.8.1. This issue affects some unknown processing of the file application.yml. Such manipulation of the argument xss.enabled leads to cross site scripting. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit has been disclosed publicly and may be used. Not independently exploitable: a defense-in-depth absence that amplifies CVE-2026-100880. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "2.6",
"pubDate": "2026-09-27T22:17:05.047Z",
"pubdate": "2026-09-27T22:17:05.047Z",
"executiveSummary": "A Cross-Site Scripting (XSS) vulnerability exists in zhistaredu StarTraining versions up to 3.8.1, identified under CVE-2026-100880.\nThe vulnerability originates from improper handling of the xss.enabled configuration parameter within the application.yml file, allowing for the injection of malicious scripts into the web application context.\nThis flaw is remotely exploitable, though it is categorized as highly complex and difficult to execute. The vulnerability serves as a critical defense-in-depth failure, potentially amplifying the impact of other security weaknesses.\nThe vulnerability is currently public, and there is no evidence of a vendor-provided fix or response. Unauthorized attackers can leverage this issue to execute arbitrary scripts in the victim's browser session, leading to potential session hijacking, data exfiltration, or unauthorized actions performed on behalf of authenticated users.\nDue to the nature of the vulnerability and the absence of a vendor patch, organizations are advised to implement immediate compensating controls to restrict unauthorized configuration access.",
"technicalDetails": "The vulnerability resides in the configuration processing logic of the zhistaredu StarTraining framework (versions <= 3.8.1). Specifically, the application parses the application.yml file to determine security posture, including the status of XSS filtering via the xss.enabled argument.\nThe root cause is a failure in the application's sanitization routine or internal logic flow, which incorrectly processes the xss.enabled flag. When manipulated, this configuration allows an attacker to bypass intended security controls that should otherwise mitigate XSS vectors.\nExploitation is achieved by targeting the processing layer of the application.yml configuration. Because the application fails to properly validate the input or state associated with the xss.enabled argument, an attacker can supply crafted payloads that the application executes within the context of the end-user's browser. The exploitability is deemed 'difficult' due to the requirements for specific environmental conditions or the necessity of chaining this flaw with other secondary vulnerabilities or misconfigurations.\nThe attack flow follows a remote exploitation pattern where an attacker identifies the target interface that reflects the state controlled by the application.yml file. Upon crafting a malicious payload that bypasses the improperly configured security filter, the attacker induces a victim to interact with the compromised endpoint. The payload is then reflected back to the user, executing arbitrary JavaScript. This effectively circumvents the defense-in-depth mechanisms that are otherwise expected to maintain site integrity.\nThe impact post-exploitation includes the potential for session token theft, unauthorized modification of the Document Object Model (DOM) to spoof content, and the initiation of unwanted requests initiated from the user's origin. The vulnerability remains critical as it allows for persistent or reflected XSS depending on how the application reflects the configured settings. Since no vendor patch exists for this specific disclosure, the application remains susceptible to remote attackers capable of influencing the server-side configuration environment."
}