Количество 2
Количество 2
CVE-2023-34927
больше 2 лет назад
Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password. This vulnerability allows attackers to arbitrarily change the victim user's password via supplying a crafted URL.
CVSS3: 6.5
EPSS: Низкий
GHSA-rwcp-qrwg-56cg
больше 2 лет назад
Casdoor Cross-Site Request Forgery vulnerability
CVSS3: 6.5
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-34927 Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password. This vulnerability allows attackers to arbitrarily change the victim user's password via supplying a crafted URL. | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
GHSA-rwcp-qrwg-56cg Casdoor Cross-Site Request Forgery vulnerability | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад |
Уязвимостей на страницу
20