Security Research

MarkUs

Zip Slip / arbitrary file write

Discovered and reported a Zip Slip path traversal in assignment configuration uploads enabling arbitrary file writes and potential remote code execution.

Critical 9.1

MarkUs

Stored XSS / instructor-context actions

Discovered and reported a stored cross-site scripting vulnerability that allowed submitted files to execute JavaScript with an instructor or grader's permissions.

High 8.0

Progress Kemp LoadMaster

Uninitialized memory / remote code execution

Credited by TrendAI ZDI for a remote code execution vulnerability caused by uninitialized memory in an enterprise load balancer.

High 7.2

MarkUs

IDOR / arbitrary submission access

Discovered and reported an IDOR in an assignment grading platform allowing authenticated users to access arbitrary student submission files.

Moderate 6.5

MarkUs

Zip bomb / denial of service

Discovered and reported missing archive extraction limits that allowed a highly compressed zip file to exhaust disk and CPU resources and make the service unavailable.

Moderate 6.5

MarkUs

YAML alias expansion / denial of service

Discovered and reported unrestricted YAML alias expansion in configuration uploads, allowing a crafted file to consume CPU and memory and cause a denial of service.

Moderate 4.9