关键漏洞信息 漏洞标题 Unauthorized Problem Creation 严重性 Severity: High (7.6/10) 影响范围 Package: main-v2 (Flagforge) Affected versions: 2.1.0 Patched versions: 2.2.0 描述与影响 Impact: 非管理员用户可以创建任意挑战,可能引入恶意、不正确或误导性内容。这会损害平台的完整性并降低合法用户之间的信任。 修复措施 Patches: 在POST /api/problems端点中实现了服务器端管理员授权检查。 参考资料 OWASP Top10 2021 - A01:2021 - Broken Access Control CWE-862: Missing Authorization CVSS v3 基本指标 Attack vector: Network Attack complexity: Low Privileges required: Low User interaction: None Scope: Unchanged Confidentiality: Low Integrity: High Availability: Low CVE ID CVE-2025-59826 弱点 Weaknesses: CWE-862 发现者 Credits: aryan4859