CVE-2026-100881
Received Received - Intake

Stored XSS in StarTraining via application.yml Configuration

Vulnerability report for CVE-2026-100881, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-27

Last updated on: 2026-09-27

Assigner: VulDB

Description

A security vulnerability has been detected in zhistaredu StarTraining up to 3.8.1. This issue affects some unknown processing of the file application.yml. Such manipulation of the argument xss.enabled leads to cross site scripting. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit has been disclosed publicly and may be used. Not independently exploitable: a defense-in-depth absence that amplifies CVE-2026-100880. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-27
Last Modified
2026-09-27
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zhistaredu startraining to 3.8.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a cross-site scripting (XSS) issue in zhistaredu StarTraining up to version 3.8.1. It involves manipulation of the xss.enabled argument in the application.yml file, leading to XSS attacks. The exploit is difficult to execute but has been publicly disclosed and may be used. It is not independently exploitable and relies on another vulnerability (CVE-2026-100880) for amplification.

Detection Guidance

This vulnerability involves a cross-site scripting (XSS) issue in zhistaredu StarTraining up to version 3.8.1, specifically through manipulation of the xss.enabled parameter in application.yml. Detection may require inspecting configuration files for unauthorized changes to xss.enabled and reviewing web application logs for suspicious input patterns. No specific commands are provided in the context.

Impact Analysis

This vulnerability could allow attackers to inject malicious scripts into web pages viewed by users, potentially stealing sensitive data or performing unauthorized actions. However, its impact is limited due to its difficult exploitability and reliance on another vulnerability for full exploitation.

Compliance Impact

This vulnerability involves a cross-site scripting (XSS) flaw in zhistaredu StarTraining due to improper handling of the xss.enabled argument in application.yml. While the vulnerability itself does not directly impact GDPR or HIPAA compliance, XSS vulnerabilities can lead to unauthorized data access or manipulation, which may violate these regulations if sensitive data is compromised. The exploitability is difficult, but public disclosure increases risk.

Mitigation Strategies

Disable or remove the StarTraining application up to version 3.8.1. Review and harden configuration files like application.yml to prevent manipulation of xss.enabled. Apply vendor patches if available or implement network-level protections to block remote exploitation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100881. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart