CVE-2023-34927: Casbin Casdoor

Medium severity, CVSS 6.5. EPSS: 3.1% chance of exploitation in the next 30 days.

Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password. This vulnerability allows attackers to arbitrarily change the victim user's password via supplying a crafted URL.

Affected products

  • Casbin Casdoor: up to and including 1.331.0

Published 2023-06-22. Last modified 2026-06-17.