« Volver al listado

Zhistaredu

Zhistaredu Startraining: vulnerabilidades y CVE

Zhistaredu Startraining tiene 7 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE7
Últimos 12 meses7
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-100881Baja (1.2)0.18%—27 sept 2026
A security vulnerability has been detected in zhistaredu StarTraining up to 3.8.1. This issue affects some unknown processing of the file application.yml. Such manipulation of the argument xss.enabled leads to cross…
CVE-2026-100880Baja (2)0.19%—27 sept 2026
A weakness has been identified in zhistaredu StarTraining up to 3.8.1. This vulnerability affects unknown code of the file du-common/src/main/java/com/edu/common/utils/file/MimeTypeUtils.java of the component Upload…
CVE-2026-100879Baja (2.1)0.20%—27 sept 2026
A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. This affects the function checkRoleAllowed of the file SysRoleServiceImpl.java of the component dataScope Endpoint. The manipulation results in…
CVE-2026-100878Baja (2.1)0.21%—27 sept 2026
A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Affected by this issue is the function SysUser.isAdmin of the file edu-common/src/main/java/com/edu/common/core/domain/entity/SysUser.java of the…
CVE-2026-97879Media (5.5)0.65%—25 sept 2026
A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. The affected element is an unknown function of the file SecurityConfig.java of the component api-docs Endpoint. Performing a manipulation…
CVE-2026-97878Media (5.5)0.63%—25 sept 2026
A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Impacted is the function anonymous of the file /druid/index.html of the component Druid Console. Such manipulation leads to missing authentication.…
CVE-2026-97877Media (5.5)0.45%—25 sept 2026
A vulnerability was determined in zhistaredu StarTraining up to 3.8.1. This issue affects the function UserLoginService.createToken of the file application.yml of the component JWT Token Handler. This manipulation of…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1078 Valid Accounts4
  2. T1190 Exploit Public-Facing Application3
  3. T1059.007 JavaScript2
  4. T1189 Drive-by Compromise2
  5. T1210 Exploitation of Remote Services2
  6. T1078.001 Default Accounts1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.