Skip to main content

Vendor archive

ctfd CVEs

Beta · best-effort

2 CVEs tagged to vendor ctfd1 Critical, 0 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2020-5290

Published Apr 1, 2020

In RedpwnCTF before version 2.3, there is a session fixation vulnerability in exploitable through the `#token=$ssid` hash when making a request to the `/verify` endpoint. An attac…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7245

Published Jan 23, 2020

Incorrect username validation in the registration process of CTFd v2.0.0 - v2.2.2 allows an attacker to take over an arbitrary account if the username is known and emails are enab…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1