Showing 2 vulnerabilities on this page for hustoj

Signals CISA KEV Ransomware Nuclei
zhblue vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

HUSTOJ has Arbitrary File Write (Zip Slip) in Problem Import Modules that leads to RCE

HUSTOF is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. Prior to version 26.01.24, the problem_import_qduoj.php and problem_import_hoj.php modules fail to properly sanitize filenames within uploaded ZIP archives. Attackers can craft a malicious ZIP file containing files with path traversal sequences (e.g., ../../shell.php). When extracted by the server, this allows writing files to arbitrary locations in the web root, leading to Remote Code Execution (R

CWE-22Jan 27, 2026
CVSS9.3v4.0EPSS7.9%PoCs2SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

HUSTOJ is Vulnerable to Stored CSV Injection (Formula Injection) in Contest Rank Export

hustoj is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. All versions are vulnerable to CSV Injection (Formula Injection) through the contest rank export functionality (contestrank.xls.php and admin/ranklist_export.php). The application fails to sanitize user-supplied input (specifically the "Nickname" field) before exporting it to an .xls file (which renders as an HTML table but is opened by Excel). If a malicious user sets their nickname to an Excel fo

CWE-1236Jan 21, 2026
CVSS5.2v4.0EPSS0.511%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX