PT-2026-23504 · Markus · Markus

Ibrah-M

+2

·

Published

2026-03-05

·

Updated

2026-03-07

·

CVE-2026-28405

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MarkUs versions prior to 2.9.1
Description MarkUs is a web application used for submitting and grading student assignments. Versions prior to 2.9.1 are susceptible to an issue where the application reads and renders the contents of student-submitted files without proper sanitization via the courses/<:course id>/assignments/<:assignment id>/submissions/html content route. The vulnerable route allows for the execution of arbitrary HTML content. The course id and assignment id are parameters used in the affected API endpoint.
Recommendations Update to version 2.9.1 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-28405
GHSA-P5PC-PXRJ-3893

Affected Products

Markus