Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/upload-resource.
| Software | From | Fixed in |
|---|---|---|
| casbin / casdoor | 1.97.3 | 1.97.3.x |
github.com/casdoor/casdoor
|
- | 1.103.1 |