Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.1, the /api/resources endpoint previously allowed POST and DELETE requests without proper authentication or authorization. This could have enabled unauthorized users to create, modify, or delete resources on the platform. The issue has been fixed in FlagForge version 2.3.1.
Metrics
Affected Vendors & Products
References
History
Mon, 29 Sep 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 29 Sep 2025 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Flagforgectf
Flagforgectf flagforge |
|
Vendors & Products |
Flagforgectf
Flagforgectf flagforge |
Sat, 27 Sep 2025 01:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.1, the /api/resources endpoint previously allowed POST and DELETE requests without proper authentication or authorization. This could have enabled unauthorized users to create, modify, or delete resources on the platform. The issue has been fixed in FlagForge version 2.3.1. | |
Title | FlagForgeCTF Unauthenticated Resource Modification/Deletion | |
Weaknesses | CWE-284 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-29T14:13:59.722Z
Reserved: 2025-09-23T14:33:49.504Z
Link: CVE-2025-59932

Updated: 2025-09-29T14:13:52.328Z

Status : Awaiting Analysis
Published: 2025-09-27T01:15:43.430
Modified: 2025-09-29T19:34:10.030
Link: CVE-2025-59932

No data.

Updated: 2025-09-29T09:29:51Z