Description
HUSTOF is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. Prior to version 26.01.24, the problem_import_qduoj.php and problem_import_hoj.php modules fail to properly sanitize filenames within uploaded ZIP archives. Attackers can craft a malicious ZIP file containing files with path traversal sequences (e.g., ../../shell.php). When extracted by the server, this allows writing files to arbitrary locations in the web root, leading to Remote Code Execution (RCE). Version 26.01.24 contains a fix for the issue.
INFO
Published Date :
2026-01-27T00:43:42.799Z
Last Modified :
2026-01-27T14:42:04.040Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2026-24479 vulnerability.
| Vendors | Products |
|---|---|
| Hustoj |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-24479.