CVE-2026-97877 | zhistaredu StarTraining up to 3.8.1 JWT Token application.yml UserLoginService.createToken user_id/company_id hard-coded password
A vulnerability was found in zhistaredu StarTraining up to 3.8.1. It has been classified as critical. This issue affects the function UserLoginService.createToken of the file application.yml of the component JWT Token Handler. This manipulation of the argument user_id/company_id causes use of hard-coded password.
This vulnerability is tracked as CVE-2026-97877. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More