Executive brief
StarTraining is an educational training platform. A flaw in its role management API endpoints allows any authenticated user to create, edit, or delete user roles without proper authorization checks. An attacker with valid login credentials could escalate privileges, grant themselves administrative permissions, and take over accounts or systems.
Technical details
The SysRoleController endpoints for role CRUD operations (add, edit, delete, dataScope) lack @PreAuthorize annotations and do not invoke the checkRoleAllowed function to validate user permissions. An authenticated attacker can POST directly to /system/role and related endpoints to manipulate role definitions. The vulnerability requires prior authentication but allows privilege escalation within the application.
Affected products
- zhistaredu StarTraining up to 3.8.1
Timeline
- 2026-09-27: disclosed