PT-2024-33270 · Putongoj · Putongoj

·

CVE-2024-48920

·

Published

2024-10-17

·

Updated

2024-10-22

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions PutongOJ versions prior to 2.1.0-beta.1
Description PutongOJ is online judging software. Unprivileged users can escalate privileges by constructing requests, leading to unauthorized access and enabling users to perform admin-level operations. This can potentially compromise sensitive data and system integrity.
Recommendations For versions prior to 2.1.0-beta.1, upgrade to version 2.1.0-beta.1 or later to fix the issue. As a temporary workaround, apply the patch from commit 211dfe9 manually to secure systems from unauthorized access risks.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-48920
GHSA-GJ6H-73C5-XW6F

Affected Products

Putongoj