CVE-2024-46242

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 7, 2025
CWE ID 1333

Summary

CVE-2024-46242 is a vulnerability affecting the CTFd platform version 3.7.3. The issue lies in the "validate_email" function found in "CTFd/utils/validators/__init__.py." An attacker can exploit this flaw by supplying a specially crafted email address during the registration process. This leads to a Regular expression Denial of Service (ReDoS) attack, causing the system to become unresponsive or consume excessive resources.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share