PT-2026-7131 · Markus · Markus

Ibrah-M

+2

·

Publicado

2026-02-09

·

Atualizado

2026-02-09

·

CVE-2026-24900

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions MarkUs versions prior to 2.9.1
Description MarkUs is a web application used for submitting and grading student assignments. A flaw exists where the select file id parameter in the ''courses/<:course id>/assignments/<:assignment id>/submissions/html content'' endpoint was not properly restricted to the user making the request. This allowed users to access submission file contents by ID without authorization. The vulnerable parameter is select file id.
Recommendations Upgrade to version 2.9.1 or later.

Exploit

Correção

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-24900
GHSA-56GH-8HMQ-7Q88

Produtos afetados

Markus