Skip to content
Noroxi

casbin records

12 published records for vendor casbin.

All records

12 records
  • The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/g

    HighCVSS 7.5Proof of conceptEPSS 55%

    casbin · casdoorJan 29, 2022

  • Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/upload-resource.

    CriticalCVSS 9.1No exploitEPSS 1%

    casbin · casdoorSep 9, 2022

  • GHSL-2024-035: Casdoor CORS misconfiguration

    HighCVSS 8.8No exploitEPSS 1%

    casbin · casdoorAug 20, 2024

  • Casdoor before v1.126.1 was discovered to contain an arbitrary file deletion vulnerability via the uploadFile function.

    HighCVSS 8.1No exploitEPSS 1%

    casbin · casdoorDec 6, 2022

  • An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method.

    HighCVSS 7.5No exploitEPSS 0%

    casbin · casdoorAug 1, 2024

  • Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password.

    MediumCVSS 6.5Proof of conceptEPSS 3%

    casbin · casdoorJun 22, 2023

  • CVE-2024-5587
    27Monitor

    Casdoor Configuration File app.conf file access

    MediumCVSS 6.9No exploitEPSS 0%

    Jun 2, 2024

  • GHSL-2024-036: Reflected XSS in QrCodePage.js

    MediumCVSS 6.1No exploitEPSS 0%

    casbin · casdoorAug 20, 2024

  • CVE-2026-6815
    23Monitor

    An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider.

    MediumCVSS 5.9Proof of conceptEPSS 1%

    casbin · casdoorMay 11, 2026

  • CVE-2026-5469
    20Monitor

    Casdoor Webhook URL server-side request forgery

    MediumCVSS 5.1No exploitEPSS 1%

    casbin · casdoorApr 3, 2026

  • Casdoor OAuth Authorization Request redirect

    LowCVSS 2.1No exploitEPSS 0%

    casbin · casdoorApr 3, 2026

  • Casdoor dangerouslySetInnerHTML cross site scripting

    LowCVSS 2.0No exploitEPSS 0%

    casbin · casdoorApr 3, 2026