PT-2026-4839 · Linux+3 · Linux+3

Ling101W

·

Published

2026-01-27

·

Updated

2026-05-22

·

CVE-2026-24479

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HUSTOF versions prior to 26.01.24
Description HUSTOF is an online judge system built on PHP, C++, MySQL, and Linux. A path traversal flaw exists in the problem import qduoj.php and problem import hoj.php modules when handling ZIP archive extractions. This allows attackers to write files to arbitrary locations within the web root by crafting malicious ZIP files containing path traversal sequences, such as ../../shell.php. Successful exploitation leads to Remote Code Execution (RCE).
Recommendations Versions prior to 26.01.24 should be updated to version 26.01.24 or later.

Exploit

Fix

RCE

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-24479
GHSA-XMGG-2RW4-7FXJ

Affected Products

Hustof
Linux
Mysql Server
Php