CVE-2024-41657
- EPSS 1.29%
- Veröffentlicht 20.08.2024 21:15:13
- Zuletzt bearbeitet 28.08.2024 16:13:35
Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earlier, a logic vulnerability exists in the beego filter CorsFilter that allows any website to make cross domain requests to Casdoor a...
CVE-2024-41658
- EPSS 0.31%
- Veröffentlicht 20.08.2024 21:15:13
- Zuletzt bearbeitet 28.08.2024 16:08:31
Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earlier, he purchase URL that is created to generate a WechatPay QR code is vulnerable to reflected XSS. When purchasing an item throu...
CVE-2024-41264
- EPSS 0.07%
- Veröffentlicht 01.08.2024 16:15:06
- Zuletzt bearbeitet 16.08.2024 16:00:36
An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method.
CVE-2024-5587
- EPSS 0.13%
- Veröffentlicht 02.06.2024 10:15:07
- Zuletzt bearbeitet 21.11.2024 09:47:58
A vulnerability was found in Casdoor up to 1.335.0. It has been classified as problematic. Affected is an unknown function of the file /conf/app.conf of the component Configuration File Handler. The manipulation leads to files or directories accessib...
CVE-2023-34927
- EPSS 0.28%
- Veröffentlicht 22.06.2023 13:15:10
- Zuletzt bearbeitet 21.11.2024 08:07:40
Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password. This vulnerability allows attackers to arbitrarily change the victim user's password via supplying a crafted URL.
CVE-2022-44942
- EPSS 0.21%
- Veröffentlicht 07.12.2022 02:15:09
- Zuletzt bearbeitet 23.04.2025 14:15:24
Casdoor before v1.126.1 was discovered to contain an arbitrary file deletion vulnerability via the uploadFile function.
CVE-2022-38638
- EPSS 0.65%
- Veröffentlicht 09.09.2022 20:15:11
- Zuletzt bearbeitet 21.11.2024 07:16:51
Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/upload-resource.
CVE-2022-24124
- EPSS 57.38%
- Veröffentlicht 29.01.2022 23:15:07
- Zuletzt bearbeitet 21.11.2024 06:49:51
The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organizations.