Access Control Flaw in CTFd Affects User Data Privacy
CVE-2024-42988
4.3MEDIUM
What is CVE-2024-42988?
An access control vulnerability exists in the ChallengeSolves API of CTFd versions 2.0.0 through 3.7.2. This issue permits authenticated users to access a list of other users who have completed particular challenges, disregarding the implemented Account Visibility settings. As a result, sensitive user data may be exposed. This vulnerability was addressed in version 3.7.3 and later, emphasizing the need for users to update their installations promptly to ensure data security.