← Back to CVE List

CVE-2023-34927

Published: 2023-06-22T13:15Z
Last Modified: 2024-11-21T08:07Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password. This vulnerability allows attackers to arbitrarily change the victim user's password via supplying a crafted URL. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt