CTFd
cpe:2.3:a:ctfd:ctfd:*:*:*:*:*:*:*
- >= 3.7.0, <= 3.7.4
A vulnerability in CTFd versions 3.7.0 prior to 3.7.4 allows authenticated users to change their assigned competition bracket and join a different team after the initial registration. This flaw arises from improper enforcement of bracket assignment rules, enabling users to reset their bracket and switch teams while a competition is active. The issue could disrupt the integrity of competition scoring and team assignments, particularly in events where brackets are used to organize prize distributions.
Exploitation of this vulnerability could lead to unauthorized changes in team bracket assignments, allowing users to switch teams during an ongoing competition, potentially for unfair advantage or to manipulate scoring outcomes.
To reproduce this vulnerability, an authenticated user can first reset their bracket assignment by setting it to null, a process that can be done through the CTFd API. After removing the bracket assignment, the user can then select a new bracket and join a different team, bypassing the intended restriction that only allows bracket changes through administrative intervention.
Users are advised to update to CTFd version 3.7.5, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.