Casdoor Cross-Site Request Forgery vulnerability
Discription

Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint `/api/set-password`. This vulnerability allows attackers to arbitrarily change the victim user’s password via supplying a crafted URL.Read More

Back to Main

Subscribe for the latest news: