MarkUs
Zip Slip / arbitrary file write
Discovered and reported a Zip Slip path traversal in assignment configuration uploads enabling arbitrary file writes and potential remote code execution.
Zip Slip / arbitrary file write
Discovered and reported a Zip Slip path traversal in assignment configuration uploads enabling arbitrary file writes and potential remote code execution.
Stored XSS / instructor-context actions
Discovered and reported a stored cross-site scripting vulnerability that allowed submitted files to execute JavaScript with an instructor or grader's permissions.
Uninitialized memory / remote code execution
Credited by TrendAI ZDI for a remote code execution vulnerability caused by uninitialized memory in an enterprise load balancer.
IDOR / arbitrary submission access
Discovered and reported an IDOR in an assignment grading platform allowing authenticated users to access arbitrary student submission files.
Zip bomb / denial of service
Discovered and reported missing archive extraction limits that allowed a highly compressed zip file to exhaust disk and CPU resources and make the service unavailable.
YAML alias expansion / denial of service
Discovered and reported unrestricted YAML alias expansion in configuration uploads, allowing a crafted file to consume CPU and memory and cause a denial of service.