CVE-2015-0914: Kozos Easyctf

Medium severity, CVSS 5.0. EPSS: 1.7% chance of exploitation in the next 30 days.

EasyCTF before 1.4 does not validate the session ID, which allows remote attackers to obtain access via a crafted HTTP request.

Affected products

  • Kozos Easyctf: up to and including 1.3

Published 2015-05-01. Last modified 2026-06-17.