Arbitrary File Read Vulnerability Found in Conference Review System HotCRp

moyix · x · 2026-08-06

A severe security vulnerability was recently discovered in HotCRp, the widely used academic conference reviewing system. Security researchers found an arbitrary file read exploit that allows unauthorized access to all uploaded files.

The exploit is straightforward: an attacker registers a submission, uploads any file to view it, and then modifies the URL parameter to something like ?docid=2. By iterating through the sequence numbers, they can read every submission PDF on the system, including those of other users and previous versions. The bug has been patched in v3.2.

Original post →

More from Safety

Safety channel →