PT-2026-3882 · Microsoft+4 · Office Excel+4

Ling101W

·

Publicado

2026-01-21

·

Atualizado

2026-02-27

·

CVE-2026-23873

CVSS v3.1

9.0

Crítica

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions hustoj (affected versions not specified)
Description hustoj is an open source online judge system built on PHP/C++/MySQL/Linux. The application is susceptible to CSV Injection (Formula Injection) through the contest rank export functionality, specifically in the contestrank.xls.php and admin/ranklist export.php files. The system does not properly sanitize user-provided input, particularly the Nickname field, before including it in exported .xls files. An attacker can exploit this by setting their nickname to an Excel formula. When an administrator opens the exported rank list in Microsoft Excel, the malicious formula will execute, potentially leading to arbitrary command execution (RCE) on the administrator’s machine or data exfiltration.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-23873
GHSA-GQWV-V7VX-2QJW

Produtos afetados

Linux
Office Excel
Mysql Server
Php
Hustoj