Flagforge

Flagforge

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Veröffentlicht 08.01.2026 00:26:46
  • Zuletzt bearbeitet 20.01.2026 18:47:56

Flag Forge is a Capture The Flag (CTF) platform. Versions 2.3.2 and below have a Regular Expression Denial of Service (ReDoS) vulnerability in the user profile API endpoint (/api/user/[username]). The application constructs a regular expression dynam...

  • EPSS 0.02%
  • Veröffentlicht 06.10.2025 16:44:27
  • Zuletzt bearbeitet 30.10.2025 13:53:37

Flag Forge is a Capture The Flag (CTF) platform. Starting in version 2.0.0 and prior to version 2.3.2, the `/api/admin/badge-templates` (GET) and `/api/admin/badge-templates/create` (POST) endpoints previously allowed access without authentication or...

  • EPSS 0.05%
  • Veröffentlicht 27.09.2025 01:15:43
  • Zuletzt bearbeitet 08.10.2025 16:56:50

Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.1, the /api/resources endpoint previously allowed POST and DELETE requests without proper authentication or authorization. This could have enabled unauthorized users t...

  • EPSS 0.01%
  • Veröffentlicht 26.09.2025 16:15:49
  • Zuletzt bearbeitet 29.01.2026 00:16:07

Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.2, the public endpoint /api/user/[username] returns user email addresses in its JSON response. The fix, intended for release in 2.3.1 but only available starting in ve...

  • EPSS 0.06%
  • Veröffentlicht 25.09.2025 16:15:35
  • Zuletzt bearbeitet 08.10.2025 16:31:08

Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.2.0 to before 2.3.1, the FlagForge web application improperly handles session invalidation. Authenticated users can continue to access protected endpoints, such as /api/profile, even...

  • EPSS 0.03%
  • Veröffentlicht 24.09.2025 21:15:32
  • Zuletzt bearbeitet 08.10.2025 16:35:24

Flag Forge is a Capture The Flag (CTF) platform. In version 2.1.0, the /api/admin/assign-badge endpoint lacks proper access control, allowing any authenticated user to assign high-privilege badges (e.g., Staff) to themselves. This could lead to privi...

  • EPSS 0.07%
  • Veröffentlicht 24.09.2025 21:15:32
  • Zuletzt bearbeitet 08.10.2025 16:34:35

Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.1.0 to before 2.3.0, the API endpoint GET /api/problems/:id returns challenge hints in plaintext within the question object, regardless of whether the user has unlocked them via poin...

  • EPSS 0.05%
  • Veröffentlicht 23.09.2025 21:15:52
  • Zuletzt bearbeitet 08.10.2025 16:35:50

Flag Forge is a Capture The Flag (CTF) platform. In version 2.1.0, non-admin users can create arbitrary challenges, potentially introducing malicious, incorrect, or misleading content. This issue has been patched in version 2.2.0.