Security Advisory

CVE-2023-34927

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-06-22 00:00:00
Last updated 2024-12-04 21:40:56
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password. This vulnerability allows attackers to arbitrarily change the victim user's password via supplying a crafted URL.