Vulnerability record · CVE-2024-47820 · published 18 November 2024
CVE-2024-47820: Markusproject markus path traversal vulnerability
Markusproject · Markus
MarkUs, a web application for the submission and grading of student assignments, is vulnerable to path traversal in versions prior to 2.4.8. Authenticated instructors may download any file on the web server MarkUs is running on, depending on the file permissions. MarkUs v2.4.8 has addressed this issue. No known workarounds are available at the application level aside from upgrading.
Description
MarkUs, a web application for the submission and grading of student assignments, is vulnerable to path traversal in versions prior to 2.4.8. Authenticated instructors may download any file on the web server MarkUs is running on, depending on the file permissions. MarkUs v2.4.8 has addressed this issue. No known workarounds are available at the application level aside from upgrading.
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/MarkUsProject/Markus/pull/7026 | Patch |
| https://github.com/MarkUsProject/Markus/security/advisories/GHSA-wq6v-vx8c-8fj8 | Third Party Advisory |
Track CVE-2024-47820 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-47820), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.