← Back

CVE-2025-59932

nvd nist
Published: Sep 27, 2025Modified: Jun 17, 2026

JSON object

Loading...
8.2
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Exploitability: 3.9 / Impact: 4.2
Source: NVD

Description

Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.1, the /api/resources endpoint previously allowed POST and DELETE requests without proper authentication or authorization. This could have enabled unauthorized users to create, modify, or delete resources on the platform. The issue has been fixed in FlagForge version 2.3.1.

Affected (1)

Products: Flagforge: Flagforge
1 product
Flagforge
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 2.0 to 2.3.1

References (1)

Timeline

No history available yet.