CVE-2024-34699 - CVE House
Back to Database
Status published Medium CVE-2024-34699

GZ::CTF allows unprivileged user can perform XSS attacks by constructing malicious team names.

Vulnerability Description

GZ::CTF is a capture the flag platform. Prior to 0.20.1, unprivileged user can perform cross-site scripting attacks on other users by constructing malicious team names. This problem has been fixed in `v0.20.1`.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-34699

Credits & Attribution

No credits recorded in the NVD database.