Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password. This vulnerability allows attackers to arbitrarily change the victim user's password via supplying a crafted URL.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Casdoor 跨站请求伪造漏洞
Vulnerability Description
Casdoor是开源的一个身份和访问管理 (IAM) / 单点登录 (SSO) 平台,带有支持 OAuth 2.0 / OIDC 和 SAML 身份验证的 Web UI 。 Casdoor v1.331.0及之前版本存在安全漏洞,该漏洞源于允许攻击者通过提供精心设计的 URL 任意更改受害者用户的密码。
CVSS Information
N/A
Vulnerability Type
N/A