CVE-2020-5290
Published Apr 1, 2020In RedpwnCTF before version 2.3, there is a session fixation vulnerability in exploitable through the `#token=$ssid` hash when making a request to the `/verify` endpoint. An attac…
Vendor archive
2 CVEs tagged to vendor ctfd — 1 Critical, 0 High, 1 Medium, 0 Low, 0 Unrated.
In RedpwnCTF before version 2.3, there is a session fixation vulnerability in exploitable through the `#token=$ssid` hash when making a request to the `/verify` endpoint. An attac…
Incorrect username validation in the registration process of CTFd v2.0.0 - v2.2.2 allows an attacker to take over an arbitrary account if the username is known and emails are enab…