Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

0X0W1Z

#26819of 53,633
9.4Total CVSS
Vulnerabilities · 1
PT-2025-40914
9.4
2025-10-06
Flagforge · Flagforge · CVE-2025-61777
**Name of the Vulnerable Software and Affected Versions** FlagForge versions 2.0.0 through 2.3.2 **Description** FlagForge, a Capture The Flag (CTF) platform, had endpoints that did not require authentication or authorization. Specifically, the `/api/admin/badge-templates` (GET) and `/api/admin/badge-templates/create` (POST) endpoints allowed unauthorized access. This allowed retrieval of badge templates and sensitive metadata (`createdBy`, `createdAt`, `updatedAt`) and the creation of arbitrary badge templates in the database. This could lead to data exposure and database pollution. The issue affected the badge system. **Recommendations** Versions prior to 2.3.2 should be updated to version 2.3.2 or later.