VYPR
Medium severity6.5NVD Advisory· Published Apr 1, 2020· Updated Jun 17, 2026

CVE-2020-5290

CVE-2020-5290

Description

In RedpwnCTF before version 2.3, there is a session fixation vulnerability in exploitable through the #token=$ssid hash when making a request to the /verify endpoint. An attacker team could potentially steal flags by, for example, exploiting a stored XSS payload in a CTF challenge so that victim teams who solve the challenge are unknowingly (and against their will) signed into the attacker team's account. Then, the attacker can gain points / value off the backs of the victims. This is patched in version 2.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • redpwn/rctfcpe-rescue2 versions
    < 2.3+ 1 more
    • (no CPE)range: < 2.3
    • (no CPE)range: <2.3
  • cpe:2.3:a:ctfd:rctf:*:*:*:*:*:*:*:*
    Range: <2.3

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.