CVE-2026-100880 | zhistaredu StarTraining up to 3.8.1 Upload Endpoint MimeTypeUtils.java File cross site scripting

SecurityVulns

A vulnerability was found in zhistaredu StarTraining up to 3.8.1. It has been rated as problematic. This vulnerability affects unknown code of the file du-common/src/main/java/com/edu/common/utils/file/MimeTypeUtils.java of the component Upload Endpoint. This manipulation of the argument File causes cross site scripting.

The identification of this vulnerability is CVE-2026-100880. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More