VYPR
Critical severity9.8NVD Advisory· Published Jan 23, 2020· Updated Jun 17, 2026

CVE-2020-7245

CVE-2020-7245

Description

Incorrect username validation in the registration process of CTFd v2.0.0 - v2.2.2 allows an attacker to take over an arbitrary account if the username is known and emails are enabled on the CTFd instance. To exploit the vulnerability, one must register with a username identical to the victim's username, but with white space inserted before and/or after the username. This will register the account with the same username as the victim. After initiating a password reset for the new account, CTFd will reset the victim's account password due to the username collision.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • CTFd/CTFd2 versions
    cpe:2.3:a:ctfd:ctfd:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:ctfd:ctfd:*:*:*:*:*:*:*:*range: >=2.0.0,<=2.2.2
    • (no CPE)range: v2.0.0 - v2.2.2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.