GHSL-2024-035: _GHSL-2024-036: CORS misconfguration and Reflected XSS in Casdoor - CVE-2024-41657, CVE-2024-41658
Published Aug 14, 2024
·Updated
Casdoor is vulnerable to a CORS misconfiguration and a reflected Cross-Site Scripting (XSS) vulnerability, both of which may allow an attacker to take actions on behalf of the signed-in user.
Affected Software
1 affected component
Casdoor Casdoor
Event History
Aug 14, 2024
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of GHSL-2024-036?
GHSL-2024-036 has a risk rating of 50, indicating a moderate severity level that requires attention.
2
How do I fix GHSL-2024-036?
To mitigate GHSL-2024-036, ensure proper CORS configurations and sanitize user inputs to prevent XSS attacks.
3
What vulnerabilities are associated with GHSL-2024-036?
GHSL-2024-036 is associated with a CORS misconfiguration and reflected XSS vulnerabilities identified as CVE-2024-41657 and CVE-2024-41658.
4
Who is affected by the vulnerability identified in GHSL-2024-036?
Users of Casdoor software are affected by the vulnerabilities identified in GHSL-2024-036.
5
What can an attacker do with the vulnerabilities in GHSL-2024-036?
An attacker exploiting GHSL-2024-036 may perform actions on behalf of the signed-in user, compromising user accounts.