PT-2025-5592 · Unknown · Pwn.College

Cjreed121

·

Published

2025-01-30

·

Updated

2025-01-31

·

CVE-2025-24885

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions pwn.college (affected versions not specified)
Description The issue is related to a lack of access control when generating custom Dojo pages without privileges, allowing users to create stored XSS. This affects the pwn.college platform, which is an education platform for learning and practicing core cybersecurity concepts in a hands-on manner.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-24885
GHSA-8M79-RMHW-RG84

Affected Products

Pwn.College