vendor:
Casdoor
by:
Van Lam Nguyen
4.1
CVSS
MEDIUM
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: Casdoor
Affected Version From: 1.901.0
Affected Version To: 1.901.0
Patch Exists: NO
Related CWE:
CPE: casdoor
Platforms Tested: Windows
2024
Casdoor 1.901.0 – Cross-Site Request Forgery (CSRF)
Casdoor version 1.901.0 and below has a Cross-Site Request Forgery (CSRF) vulnerability in the /api/set-password endpoint. This vulnerability allows attackers to change a victim user's password through a maliciously crafted URL.
Mitigation:
To mitigate this vulnerability, it is recommended to implement anti-CSRF tokens in the application to validate and authenticate requests, ensuring that actions are performed by the intended user.