The Great Password Heist: Casdoor 1.901.0 Hit by CSRF Vulnerability!
Casdoor v1.901.0 fell victim to Cross-Site Request Forgery (CSRF), allowing password changes with a mere click of a crafted URL. Remember, in the world of cybersecurity, even a simple URL can be a supervillain!

Hot Take:
Well, it seems like Casdoor’s security guard decided to take a nap! With the latest CSRF vulnerability, it’s like leaving your front door wide open and inviting hackers to change your password to “hacked.” Talk about an open-door policy!
Key Points:
- Casdoor v1.901.0 has a CSRF vulnerability in the /api/set-password endpoint.
- Attackers can change a victim’s password with a crafted URL.
- The vulnerability bypasses old password authentication.
- A proof of concept demonstrates the exploit using a simple HTML form.
- The exploit creates a new user with dangerous credentials if executed while logged in.
Already a member? Log in here