While assignment of a user to a team (bracket) in CTFd ...
Moderate severity
Unreviewed
Published
Jan 2, 2025
to the GitHub Advisory Database
•
Updated Jan 2, 2025
Description
Published by the National Vulnerability Database
Jan 2, 2025
Published to the GitHub Advisory Database
Jan 2, 2025
Last updated
Jan 2, 2025
While assignment of a user to a team (bracket) in CTFd should be possible only once, at the registration, a flaw in logic implementation allows an authenticated user to reset it's bracket and then pick a new one, joining another team while a competition is already ongoing.
This issue impacts releases from 3.7.0 up to 3.7.4 and was addressed by pull request 2636 CTFd/CTFd#2636 included in 3.7.5 release.
References