Record summary

CVE-2019-17538 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file reading via the web/polygon/problem/viewfile?id=1&name=../ substring.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 8, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHJiangnan Online Judge 0.8.0 - Local File InclusionCVSS 7.5

Jiangnan Online Judge (aka jnoj) 0.8.0 is susceptible to local file inclusion via web/polygon/problem/viewfile?id=1&name=../.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information, including system files and credentials.

Remediation

Upgrade Jiangnan Online Judge to a patched version or apply the necessary security patches to fix the Local File Inclusion vulnerability.

WeaknessesCWE-22
Authorspussycat0x
Template tagscve2019cvejnojlfivkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:jnoj:jiangnan_online_judge:0.8.0:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2