Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rmxx-v9rj-vpvg

Опубликовано: 11 мая 2026
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Casdoor: Arbitrary file write possible through Local File System storage provider

An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path sanitization, an authenticated attacker with administrative privileges can perform a Path Traversal attack to create or overwrite arbitrary files anywhere on the host filesystem, bypassing the application's intended storage sandbox.

Пакеты

Наименование

github.com/casdoor/casdoor

go
Затронутые версииВерсия исправления

<= 1.1000.0

Отсутствует

EPSS

Процентиль: 41%
0.00513
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.9
nvd
3 месяца назад

An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path sanitization, an authenticated attacker with administrative privileges can perform a Path Traversal attack to create or overwrite arbitrary files anywhere on the host filesystem, bypassing the application's intended storage sandbox.

EPSS

Процентиль: 41%
0.00513
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-22