VYPR

Rctf

by CTFd

CVEs (1)

  • CVE-2020-5290MedApr 1, 2020
    risk 0.42cvss 6.5epss 0.01

    In RedpwnCTF before version 2.3, there is a session fixation vulnerability in exploitable through the `#token=$ssid` hash when making a request to the `/verify` endpoint. An attacker team could potentially steal flags by, for example, exploiting a stored XSS payload in a CTF…