zhblue Vulnerabilities and Affected Products
Vulnerabilities associated with hustoj.
Products
Clear product- hustoj2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-24479CRITICAL | HUSTOJ has Arbitrary File Write (Zip Slip) in Problem Import Modules that leads to RCEHUSTOF is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. Prior to version 26.01.24, the problem_import_qduoj.php and problem_import_hoj.php modules fail to properly sanitize filenames within uploaded ZIP archives. Attackers can craft a malicious ZIP file containing files with path traversal sequences (e.g., ../../shell.php). When extracted by the server, this allows writing files to arbitrary locations in the web root, leading to Remote Code Execution (R… CWE-22Jan 27, 2026 | CVSS9.3v4.0 | EPSS7.9% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-23873MEDIUM | HUSTOJ is Vulnerable to Stored CSV Injection (Formula Injection) in Contest Rank Exporthustoj is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. All versions are vulnerable to CSV Injection (Formula Injection) through the contest rank export functionality (contestrank.xls.php and admin/ranklist_export.php). The application fails to sanitize user-supplied input (specifically the "Nickname" field) before exporting it to an .xls file (which renders as an HTML table but is opened by Excel). If a malicious user sets their nickname to an Excel fo… CWE-1236Jan 21, 2026 | CVSS5.2v4.0 | EPSS0.511% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |