Description
GZ::CTF is a capture the flag platform. Prior to 0.20.1, unprivileged user can perform cross-site scripting attacks on other users by constructing malicious team names. This problem has been fixed in `v0.20.1`.
Problem types
CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
References
github.com/.../GZCTF/security/advisories/GHSA-p6rq-5x3x-rmhh
github.com/...ommit/31e775b65cddf82a567d68dcdc78c1739b746346
github.com/.../GZCTF/security/advisories/GHSA-p6rq-5x3x-rmhh
github.com/...ommit/31e775b65cddf82a567d68dcdc78c1739b746346