While assignment of a user to a team (bracket) in CTFd  should be possible only once, at the registration, a flaw in logic implementation allows an authenticated user to reset it's bracket and then pick a new one, joining another team while a competition is already ongoing.
This issue impacts releases from 3.7.0 up to 3.7.4 and was addressed by  pull request 2636 https://github.com/CTFd/CTFd/pull/2636  included in 3.7.5 release.
                
            CVSS
                No CVSS.
References
                    Configurations
                    No configuration.
History
                    02 Jan 2025, 18:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://seclists.org/fulldisclosure/2024/Dec/21 - | 
02 Jan 2025, 17:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-01-02 17:15
Updated : 2025-01-02 18:15
NVD link : CVE-2024-11716
Mitre link : CVE-2024-11716
CVE.ORG link : CVE-2024-11716
JSON object : View
Products Affected
                No product.
CWE
                
                    
                        
                        CWE-837
                        
            Improper Enforcement of a Single, Unique Action
