VYPR

StarTraining

by Zhistaredu

CVEs (2)

  • CVE-2026-97878HigSep 25, 2026
    risk 0.47cvss 7.3epss —

    A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Impacted is the function anonymous of the file /druid/index.html of the component Druid Console. Such manipulation leads to missing authentication. The attack may be performed from remote. The exploit is…

  • CVE-2026-97877HigSep 25, 2026
    risk 0.47cvss 7.3epss —

    A vulnerability was determined in zhistaredu StarTraining up to 3.8.1. This issue affects the function UserLoginService.createToken of the file application.yml of the component JWT Token Handler. This manipulation of the argument user_id/company_id causes use of hard-coded…