CVE-2019-17538
jnoj jiangnan_online_judge Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2019-17538 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file reading via the web/polygon/problem/viewfile?id=1&name=../ substring.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 8, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
jiangnan_online_judgeBrowse jnoj / jiangnan_online_judge | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHJiangnan Online Judge 0.8.0 - Local File InclusionCVSS 7.5
Jiangnan Online Judge (aka jnoj) 0.8.0 is susceptible to local file inclusion via web/polygon/problem/viewfile?id=1&name=../.
Impact
Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information, including system files and credentials.
Remediation
Upgrade Jiangnan Online Judge to a patched version or apply the necessary security patches to fix the Local File Inclusion vulnerability.
Source: ProjectDiscovery