Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-59833

Опубликовано: 24 сент. 2025
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.1.0 to before 2.3.0, the API endpoint GET /api/problems/:id returns challenge hints in plaintext within the question object, regardless of whether the user has unlocked them via point deduction. Users can view all hints for free, undermining the business logic of the platform and reducing the integrity of the challenge system. This issue has been patched in version 2.3.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:flagforge:flagforge:*:*:*:*:*:*:*:*
Версия от 2.1.0 (включая) до 2.3 (исключая)

EPSS

Процентиль: 19%
0.00059
Низкий

7.5 High

CVSS3

Дефекты

CWE-200

EPSS

Процентиль: 19%
0.00059
Низкий

7.5 High

CVSS3

Дефекты

CWE-200