Casdoor是Casdoor组织开源的一个支持多种身份验证和授权协议的开源平台。 Casdoor v3.115.0及之前版本存在安全漏洞,该漏洞源于授权(基于?id=)与操作(基于请求体)之间的不匹配,可能导致非全局组织管理员绕过租户边界,在其他租户中删除、创建或修改资源。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet