CVE-2018-16367: Qduoj Onlinejudge
Critical severity, CVSS 9.9. EPSS: 2.2% chance of exploitation in the next 30 days.
In OnlineJudge 2.0, the sandbox has an incorrect access control vulnerability that can write a file anywhere. A user can write a directory listing to /tmp, and can leak file data with a #include.
Affected products
- Qduoj Onlinejudge: version 2.0 only
Published 2018-09-02. Last modified 2026-06-17.