VDB

CVE-2026-4200

CVE-2026-4200 PUBLISHED CVSS 5.5 MEDIUM

A security flaw has been discovered in glowxq glowxq-oj up to 6f7c723090472057252040fd2bbbdaa1b5ed2393. This affects the function uploadTestcaseZipUrl of the file business/business-oj/src/main/java/com/glowxq/oj/problem/controller/ProblemCaseController.java. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.

EPSS 0.47% · 38.9th percentile

Risk Scores

CVSS 4.0
5.5
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Score
0.47%
38.9th percentile

Affected Products

VendorProductVersions
glowxqglowxq-oj6f7c723090472057252040fd2bbbdaa1b5ed2393, 6f7c723090472057252040fd2bbbdaa1b5ed2393, 6f7c723090472057252040fd2bbbdaa1b5ed2393

Timeline

  • Mar 16, 2026 EPSS Score
  • Mar 16, 2026 CVE Published
  • Mar 16, 2026 CVE Updated
  • Mar 17, 2026 EPSS Score
  • Mar 17, 2026 Coalition ESS Score
  • Mar 19, 2026 EPSS Score
  • Mar 20, 2026 EPSS Score
  • Mar 22, 2026 EPSS Score
  • Mar 23, 2026 EPSS Score
  • Mar 24, 2026 EPSS Score
  • Mar 29, 2026 Security Advisory
  • May 18, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›