Executive brief
zhistaredu StarTraining is a training management platform. The authRole endpoint contains a broken access control check that allows authenticated users to reassign roles to any other user, enabling privilege escalation from a low-privilege account to administrator. An attacker with a basic user account can exploit this remotely to gain full administrative control of the system.
Technical details
The SysUser.isAdmin() method incorrectly returns true for any non-null userId instead of validating actual admin privileges, causing the checkUserDataScope() authorization check to fail. The PUT /system/user/authRole endpoint lacks proper authorization enforcement (@PreAuthorize annotation) and allows any authenticated user to modify role assignments for arbitrary user IDs. An authenticated attacker can reassign themselves or other users to administrative roles, achieving privilege escalation.
Affected products
- zhistaredu StarTraining up to 3.8.1
Timeline
- 2026-09-27: disclosed: Vulnerability publicly disclosed; vendor did not respond to early disclosure