security research.

MarkUs

Critical · 9.1

Zip Slip / arbitrary file write

Discovered and reported a Zip Slip path traversal in assignment configuration uploads enabling arbitrary file writes and potential remote code execution.

write-up

MarkUs

High · 8.0

Stored XSS / instructor-context actions

Discovered and reported a stored cross-site scripting vulnerability that allowed submitted files to execute JavaScript with an instructor or grader's permissions.

Progress Kemp LoadMaster

High · 7.2

Uninitialized memory / remote code execution

Credited by TrendAI ZDI for a remote code execution vulnerability caused by uninitialized memory in an enterprise load balancer.

MarkUs

Moderate · 6.5

IDOR / arbitrary submission access

Discovered and reported an IDOR in an assignment grading platform allowing authenticated users to access arbitrary student submission files.

MarkUs

Moderate · 6.5

Zip bomb / denial of service

Discovered and reported missing archive extraction limits that allowed a highly compressed zip file to exhaust disk and CPU resources and make the service unavailable.

MarkUs

Moderate · 4.9

YAML alias expansion / denial of service

Discovered and reported unrestricted YAML alias expansion in configuration uploads, allowing a crafted file to consume CPU and memory and cause a denial of service.