Lack of access control in ChallengeSolves (/api/v1...
Moderate severity
Unreviewed
Published
Oct 9, 2024
to the GitHub Advisory Database
•
Updated Feb 11, 2025
Description
Published by the National Vulnerability Database
Oct 9, 2024
Published to the GitHub Advisory Database
Oct 9, 2024
Last updated
Feb 11, 2025
Lack of access control in ChallengeSolves (/api/v1/challenges//solves) of CTFd v2.0.0 - v3.7.2 allows authenticated users to retrieve a list of users who have solved the challenge, regardless of the Account Visibility settings. The issue is fixed in v3.7.3+.
References