CVE-2023-34927: Casdoor < v1.331.0 - '/api/set-password' CSRF
Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password. This vulnerability allows attackers to arbitrarily change the victim user's password via supplying a crafted URL.
Other sources
Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password. This vulnerability allows attackers to arbitrarily change the victim user's password via supplying a crafted URL.
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-34927?
CVE-2023-34927 is classified as a high severity vulnerability due to the potential for attackers to change user passwords without their consent.
How do I fix CVE-2023-34927?
To mitigate CVE-2023-34927, upgrade Casdoor to version 1.332.0 or later where this vulnerability is addressed.
What type of attack does CVE-2023-34927 enable?
CVE-2023-34927 enables Cross-Site Request Forgery (CSRF) attacks, allowing attackers to change victim users' passwords.
Which versions of Casdoor are affected by CVE-2023-34927?
CVE-2023-34927 affects Casdoor versions 1.331.0 and earlier.
What is the vulnerable endpoint in CVE-2023-34927?
The vulnerable endpoint in CVE-2023-34927 is /api/set-password.