Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Sarthakkc36

#25789of 53,633
9.8Total CVSS
Vulnerabilities · 1
PT-2025-39348
9.8
2025-09-24
Flagforge · Flagforge · CVE-2025-59827
**Name of the Vulnerable Software and Affected Versions** Flag Forge versions prior to 2.2.0 **Description** Flag Forge is a Capture The Flag (CTF) platform. The `/api/admin/assign-badge` endpoint lacks proper access control, allowing any authenticated user to assign high-privilege badges, such as Staff, to themselves. This can lead to privilege escalation and impersonation of administrative roles. **Recommendations** Versions prior to 2.2.0 should be updated to version 2.2.0 or later.