Published: 2015/05/01  Last Updated: 2015/05/01

Information from Hiroaki Sakai

Vulnerability ID:JVN#96439865
Title:EasyCTF vulnerable to session management
Status:Vulnerable

This is a statement from the vendor itself with no modification by JPCERT/CC.

Somebody can login by invalid session ID.

Incorrect version: before EasyCTF-1.3
Correct version: after EasyCTF-1.4