漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
While assignment of a user to a team (bracket) in CTFd should be possible only once, at the registration, a flaw in logic implementation allows an authenticated user to reset it's bracket and then pick a new one, joining another team while a competition is already ongoing. This issue impacts releases from 3.7.0 up to 3.7.4 and was addressed by pull request 2636 https://github.com/CTFd/CTFd/pull/2636 included in 3.7.5 release.
CVSS Information
N/A
Vulnerability Type
CWE-837
Vulnerability Title
CTFd 安全漏洞
Vulnerability Description
CTFd是CTFd开源的一个 Capture The Flag 框架。 CTFd 3.7.0至3.7.4版本存在安全漏洞,该漏洞源于逻辑实现上存在缺陷,允许已认证用户在比赛进行期间重置其团队(bracket)并加入新团队。
CVSS Information
N/A
Vulnerability Type
N/A