CVE-2025-23001: Medium severity ctfd vulnerability
A Host header injection vulnerability exists in CTFd 3.7.5, due to the application failing to properly validate or sanitize the Host header. An attacker can manipulate the Host header in HTTP requests, which may lead to phishing attacks, reset password, or cache poisoning. NOTE: the Supplier's position is that the end user is supposed to edit the NGINX configuration template to set servername (with this setting, Host header injection cannot occur).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23001?
CVE-2025-23001 has a high severity level due to its potential for exploitation in phishing attacks, password resets, and cache poisoning.
How do I fix CVE-2025-23001?
To fix CVE-2025-23001, update to the latest version of CTFd where the Host header is properly validated and sanitized.
What versions of CTFd are affected by CVE-2025-23001?
CVE-2025-23001 affects CTFd version 3.7.5 and earlier versions.
What types of attacks can be launched using CVE-2025-23001?
CVE-2025-23001 can be exploited for phishing attacks, password reset manipulation, and cache poisoning.
Is CTFd safe to use if I am on version 3.7.5, knowing about CVE-2025-23001?
CTFd version 3.7.5 is not safe to use because of the confirmed vulnerabilities outlined in CVE-2025-23001.