PT-2026-79787 · Ctfd · Ctfd
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
CTFd versions prior to 3.8.5
Description
An open redirect issue exists where remote attackers can manipulate the
Next argument. This occurs within the is safe url() function located in the CTFd/utils/validators/ init .py file.Recommendations
Update to a version newer than 3.8.4.
As a temporary mitigation, restrict or validate the input passed to the
Next argument to prevent redirection to untrusted domains.Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ctfd