CVE-2026-25057 | MarkUsProject Markus up to 2.9.0 upload_config_files path traversal
A vulnerability identified as problematic has been detected in MarkUsProject Markus up to 2.9.0. Affected is an unknown function of the file courses//assignments/upload_config_files. This manipulation causes relative path traversal.
This vulnerability is registered as CVE-2026-25057. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.