CVE-2026-100881 | zhistaredu StarTraining up to 3.8.1 application.yml xss.enabled cross site scripting

SecurityVulns

A vulnerability categorized as problematic has been discovered in zhistaredu StarTraining up to 3.8.1. This issue affects some unknown processing of the file application.yml. Such manipulation of the argument xss.enabled leads to cross site scripting.

This vulnerability is referenced as CVE-2026-100881. It is possible to launch the attack remotely. Furthermore, an exploit is available.

Not independently exploitable: a defense-in-depth absence that amplifies CVE-2026-100880. The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More