Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-59827

Опубликовано: 24 сент. 2025
Источник: nvd
CVSS3: 8.2
CVSS3: 9.8
EPSS Низкий

Описание

Flag Forge is a Capture The Flag (CTF) platform. In version 2.1.0, the /api/admin/assign-badge endpoint lacks proper access control, allowing any authenticated user to assign high-privilege badges (e.g., Staff) to themselves. This could lead to privilege escalation and impersonation of administrative roles. This issue has been patched in version 2.2.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:flagforge:flagforge:2.1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 18%
0.00056
Низкий

8.2 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-862

EPSS

Процентиль: 18%
0.00056
Низкий

8.2 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-862