PT-2020-18380 · Redpwn · Redpwnctf
Arinerron
·
Published
2020-04-01
·
Updated
2020-04-03
·
CVE-2020-5290
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
RedpwnCTF versions prior to 2.3
Description
The issue is related to a session fixation vulnerability that can be exploited through the
#token=$ssid hash when making a request to the "/verify" endpoint. An attacker could potentially steal flags by exploiting a stored XSS payload in a CTF challenge, causing victim teams to be signed into the attacker's account unknowingly. This allows the attacker to gain points from the victims.Recommendations
For versions prior to 2.3, update to version 2.3 to resolve the issue. As a temporary workaround, consider restricting access to the "/verify" endpoint or disabling the use of the
#token=$ssid hash until the update is applied. Avoid using the #token=$ssid hash in the "/verify" endpoint until the issue is resolved.Exploit
Fix
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Redpwnctf