Impact
A flaw in the StarTraining configuration file causes the xss.enabled option to be ignored, allowing attackers to inject malicious scripts that execute in the context of legitimate users. The vulnerability is delivered via the application.yml file, can be triggered remotely, and is deemed difficult to exploit because it requires specific manipulation of the configuration. The weakness is classified under CWE‑79 (XSS) and CWE‑94 (Code Injection), indicating that unsanitized input reaches a scripting context and that code may be evaluated.
Affected Systems
The issue affects the StarTraining application from zhistaredu, with affected versions up to 3.8.1. No other vendors or products are listed. The known CPE identifies the product as cpe:2.3:a:zhistaredu:startraining:*:*:*:*:*:*:*.*
Risk and Exploitability
The CVSS score of 2.1 reflects a low technical severity, and no EPSS data is available. The vulnerability is not listed in the CISA KEV catalog. The exploit is publicly disclosed but complex and considered difficult, suggesting limited real‑world exploitation. Nonetheless, attackers that succeed could hijack user sessions or execute arbitrary JavaScript, posing a confidentiality and integrity threat to affected users.
OpenCVE Enrichment