CVE-2025-24886

CVSS 3.1 Score 7.7 of 10 (high)

Details

Published Jan 30, 2025
CWE ID 61
CWE ID 200

Summary

CVE-2025-24886 is a vulnerability affecting the pwn.college education platform. This issue enables users, including non-administrators, to perform a Local File Inclusion (LFI) attack. By crafting a repository with malicious symlinks, a user can trick the CTFd container into accessing sensitive files. The platform fails to adequately check user-specified dojos for incorrect symlinks during repository cloning or updates, leading to potential data exposure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share