Описание
Flag Forge is a Capture The Flag (CTF) platform. In version 2.1.0, the /api/admin/assign-badge endpoint lacks proper access control, allowing any authenticated user to assign high-privilege badges (e.g., Staff) to themselves. This could lead to privilege escalation and impersonation of administrative roles. This issue has been patched in version 2.2.0.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:flagforge:flagforge:2.1.0:*:*:*:*:*:*:*
EPSS
Процентиль: 18%
0.00056
Низкий
8.2 High
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-862
EPSS
Процентиль: 18%
0.00056
Низкий
8.2 High
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-862