Impact
A vulnerability was identified in the StarTraining platform that allows an attacker to bypass access controls by manipulating the checkRoleAllowed method in the SysRoleServiceImpl class of the dataScope endpoint. According to the description, the flaw results in missing authorization checks, enabling unauthorized users to access or modify data through this endpoint. The weakness corresponds to CWE‑862 and CWE‑863.
Affected Systems
The affected product is zhistaredu StarTraining, versions up to and including 3.8.1. No other versions or subcomponents are specified as affected. Users running these versions should consider this system vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact, and the EPSS score is not available. The vulnerability is not listed in CISA’s KEV catalog. Exploit code has been released publicly and can be triggered remotely. Given that the attack can be performed from outside the network, administrators should consider the risk moderate to high in environments where the dataScope endpoint is exposed. No official patch or workaround has been published by the vendor.
OpenCVE Enrichment