Regular Expression Denial of Service in CTFd by the Vendor CTFd
CVE-2024-46242
7.5HIGH
What is CVE-2024-46242?
A vulnerability exists in the validate_email function of CTFd version 3.7.3, where an attacker can exploit the system by submitting a specially crafted email address during registration. This flaw opens the potential for a Regular Expression Denial of Service (ReDoS) attack, effectively causing service disruptions. By leveraging this issue, an attacker can manipulate the validation process, leading to an excessive consumption of resources and potentially affecting the overall performance of the application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
