7.1
CVE-2025-29419
- EPSS 0.15%
- Veröffentlicht 26.08.2026 00:00:00
- Zuletzt bearbeitet 08.09.2026 19:42:20
- Erkennungen
CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.045 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 7.1 | 2.8 | 4.2 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
|
CWE-300 Channel Accessible by Non-Endpoint
The product does not adequately verify the identity of actors at both ends of a communication channel, or does not adequately ensure the integrity of the channel, in a way that allows the channel to be accessed or influenced by an actor that is not an endpoint.
http://ctfd.com
https://github.com/QingdaoU/OnlineJudge
https://github.com/CTFd/CTFd
https://thewindghost.github.io/#cve-2025-29419