PT-2024-33270 · Putongoj · Putongoj
Luoingly
·
Published
2024-10-17
·
Updated
2024-10-22
·
CVE-2024-48920
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
PutongOJ versions prior to 2.1.0-beta.1
Description
PutongOJ is online judging software. Unprivileged users can escalate privileges by constructing requests, leading to unauthorized access and enabling users to perform admin-level operations. This can potentially compromise sensitive data and system integrity.
Recommendations
For versions prior to 2.1.0-beta.1, upgrade to version 2.1.0-beta.1 or later to fix the issue.
As a temporary workaround, apply the patch from commit
211dfe9 manually to secure systems from unauthorized access risks.Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Putongoj