PT-2026-7131 · Markus · Markus

Ibrah-M

+2

·

Published

2026-02-09

·

Updated

2026-02-09

·

CVE-2026-24900

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions MarkUs versions prior to 2.9.1
Description MarkUs is a web application used for submitting and grading student assignments. A flaw exists where the select file id parameter in the ''courses/<:course id>/assignments/<:assignment id>/submissions/html content'' endpoint was not properly restricted to the user making the request. This allowed users to access submission file contents by ID without authorization. The vulnerable parameter is select file id.
Recommendations Upgrade to version 2.9.1 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-24900
GHSA-56GH-8HMQ-7Q88

Affected Products

Markus