Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password. This vulnerability allows attackers to arbitrarily change the victim user's password via supplying a crafted URL.
| Software | From | Fixed in |
|---|---|---|
github.com/casdoor/casdoor
|
- | 1.331.0.x |
| casbin / casdoor | - | 1.331.0.x |