Exploits / Vulnerability Discovered : 2024-04-02 |
Type : webapps |
Platform : go
This exploit / vulnerability Casdoor < v1.331.0 /api/setpassword csrf is for educational purposes only and if it is used you will do on your own risk!
Overview
==================================================
Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password.
This vulnerability allows attackers to arbitrarily change the victim user's password via supplying a crafted URL.
Proof of Concept
==================================================
Made an unauthorized request to /api/set-password that bypassed the old password entry authentication step