cve/2023/CVE-2023-34927.md
2024-06-18 02:51:15 +02:00

706 B

CVE-2023-34927

Description

Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password. This vulnerability allows attackers to arbitrarily change the victim user's password via supplying a crafted URL.

POC

Reference

Github

No PoCs found on GitHub currently.