Impact
CTFd version 3.7.6 is susceptible to a man‑in‑the‑middle attack, allowing an adversary to intercept, modify or inject traffic between the client and server. This flaw compromises the confidentiality and integrity of all transmitted data, potentially exposing credentials, challenge submissions, or any sensitive information exchanged during competition use. The vulnerability arises from insufficient or improper encryption handling, enabling an attacker to position themselves between legitimate participants and the platform. This attack leverages weaknesses identified by CWE-300, which relate to insecure transport protocols.
Affected Systems
The only explicitly affected product is the open‑source CTFd platform running version 3.7.6. Any deployment using this exact version, regardless of hosting environment, is vulnerable if traffic is not protected by robust TLS or other secure transport mechanisms.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, and the EPSS score of <1% suggests a low probability of exploitation at present. The vulnerability can be exploited when an attacker can intercept traffic to the vulnerable instance, for example by redirecting DNS or capturing unencrypted connections. The flaw is not yet listed in the CISA KEV catalog.
OpenCVE Enrichment