Security Advisory

CVE-2023-34927

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-06-22 00:00:00
Last updated 2024-12-04 21:40:56
Assigner mitre
State PUBLISHED

Description

Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password. This vulnerability allows attackers to arbitrarily change the victim users password via supplying a crafted URL.