CVE-2024-11717 — Tokens in CTFd used for account activation and password resetting can be used interchangeably for these operations. When used, they are sent to the server as a GET parameter and they are not single us — CVE Database · The Intelligence Room