CVE-2023-34927: Casbin Casdoor
Medium severity, CVSS 6.5. EPSS: 3.1% chance of exploitation in the next 30 days.
Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password. This vulnerability allows attackers to arbitrarily change the victim user's password via supplying a crafted URL.
Affected products
- Casbin Casdoor: up to and including 1.331.0
Published 2023-06-22. Last modified 2026-06-17.