PT-2024-33270 · Putongoj · Putongoj

Luoingly

·

Published

2024-10-17

·

Updated

2024-10-22

·

CVE-2024-48920

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions PutongOJ versions prior to 2.1.0-beta.1
Description PutongOJ is online judging software. Unprivileged users can escalate privileges by constructing requests, leading to unauthorized access and enabling users to perform admin-level operations. This can potentially compromise sensitive data and system integrity.
Recommendations For versions prior to 2.1.0-beta.1, upgrade to version 2.1.0-beta.1 or later to fix the issue. As a temporary workaround, apply the patch from commit 211dfe9 manually to secure systems from unauthorized access risks.

Exploit

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2024-48920
GHSA-GJ6H-73C5-XW6F

Affected Products

Putongoj