PT-2026-23628 · Markus · Markus

Ibrah-M

+1

·

Publicado

2026-03-06

·

Atualizado

2026-03-12

·

CVE-2026-27807

CVSS v3.1

4.9

Média

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions MarkUs versions prior to 2.9.4
Description MarkUs is a web application used for submitting and grading student assignments. Versions of MarkUs before 2.9.4 allow course instructors to upload YAML files to create or update entities like assignment settings. The application parses these YAML files with aliases enabled, which can lead to issues. This issue was addressed in version 2.9.4. YAML aliases allow defining reusable parts within a YAML file, potentially leading to unintended consequences if not handled securely during parsing.
Recommendations Update to version 2.9.4 or later.

Exploit

Correção

XML Entity Expansion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-27807
GHSA-M9RX-85MX-Q9H6

Produtos afetados

Markus