Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.1, the /api/resources endpoint previously allowed POST and DELETE requests without proper authentication or authorization. This could have enabled unauthorized users to create, modify, or delete resources on the platform. The issue has been fixed in FlagForge version 2.3.1.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 27 Sep 2025 01:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.1, the /api/resources endpoint previously allowed POST and DELETE requests without proper authentication or authorization. This could have enabled unauthorized users to create, modify, or delete resources on the platform. The issue has been fixed in FlagForge version 2.3.1. | |
Title | FlagForgeCTF Unauthenticated Resource Modification/Deletion | |
Weaknesses | CWE-284 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-27T00:51:01.805Z
Reserved: 2025-09-23T14:33:49.504Z
Link: CVE-2025-59932

No data.

Status : Received
Published: 2025-09-27T01:15:43.430
Modified: 2025-09-27T01:15:43.430
Link: CVE-2025-59932

No data.

No data.