CVE-2025-59932
FlagForgeCTF Unauthenticated Resource Modification/Deletion
Vexday Risk Score
21Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 8.6EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
27 set 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.1, the /api/resources endpoint previously allowed POST and DELETE requests without proper authentication or authorization. This could have enabled unauthorized users to create, modify, or delete resources on the platform. The issue has been fixed in FlagForge version 2.3.1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
Produtos afetados
FlagForgeCTF · flagForgeQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →