While assignment of a user to a team (bracket) in CTFd should be possible only once, at the registration, a flaw in logic implementation allows an authenticated user to reset it's bracket and then pick a new one, joining another team while a competition is already ongoing.
This issue impacts releases from 3.7.0 up to 3.7.4 and was addressed by pull request 2636 https://github.com/CTFd/CTFd/pull/2636 included in 3.7.5 release.
Metrics
Affected Vendors & Products
References
History
Mon, 03 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 02 Jan 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 02 Jan 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | While assignment of a user to a team (bracket) in CTFd should be possible only once, at the registration, a flaw in logic implementation allows an authenticated user to reset it's bracket and then pick a new one, joining another team while a competition is already ongoing. This issue impacts releases from 3.7.0 up to 3.7.4 and was addressed by pull request 2636 https://github.com/CTFd/CTFd/pull/2636 included in 3.7.5 release. | |
| Weaknesses | CWE-837 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published: 2025-01-02T16:07:46.868Z
Updated: 2025-11-03T21:52:05.067Z
Reserved: 2024-11-25T17:36:38.975Z
Link: CVE-2024-11716
Updated: 2025-11-03T21:52:05.067Z
Status : Awaiting Analysis
Published: 2025-01-02T17:15:07.090
Modified: 2025-11-03T22:16:38.667
Link: CVE-2024-11716
No data.