CVE-2018-16367: Qduoj Onlinejudge

Critical severity, CVSS 9.9. EPSS: 2.2% chance of exploitation in the next 30 days.

In OnlineJudge 2.0, the sandbox has an incorrect access control vulnerability that can write a file anywhere. A user can write a directory listing to /tmp, and can leak file data with a #include.

Affected products

  • Qduoj Onlinejudge: version 2.0 only

Published 2018-09-02. Last modified 2026-06-17.