Jnoj's vulnerability profile centers on its Jiangnan Online Judge platform, a web-based competitive programming and assessment system where disclosures cluster around application-layer input-handling and file-management weaknesses. The recurring weakness classes—cross-site scripting, path traversal, and unrestricted dangerous file uploads—are characteristic of web applications that accept user submissions and reflect typical attack surface in judge and learning-management software; vulnerabilities here frequently acquire public exploit code. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jnoj over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-17538HIGH Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file reading via the web/polygon/problem/viewfile?id=1&name=../ substring. | Oct 13, 2019 | 7.5 | 40 | NO | YES |
CVE-2019-17490HIGH app\modules\polygon\controllers\ProblemController in Jiangnan Online Judge (aka jnoj) 0.8.0 allows arbitrary file upload, as demonstrated by PHP code (with a .php filename but the | Oct 10, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-17537HIGH Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file deletion via the web/polygon/problem/deletefile?id=1&name=../ substring. | Oct 13, 2019 | 7.5 | 24 | NO | NO |
CVE-2019-17493MEDIUM Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[sample_input] parameter to web/admin/problem/create or web/polygon/problem/update. | Oct 10, 2019 | 6.1 | 21 | NO | NO |
CVE-2019-17491MEDIUM Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[description] parameter to web/admin/problem/create or web/polygon/problem/update. | Oct 10, 2019 | 6.1 | 21 | NO | NO |
CVE-2019-17489MEDIUM Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[title] parameter to web/polygon/problem/create or web/polygon/problem/update or web/admin/problem/create. | Oct 10, 2019 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jnoj.
Media articles that mention a CVE ID that affects a product developed by Jnoj — matched by CVE ID, not by vendor name.