Vulnerabilities (CVE)

Filtered by vendor Casbin Subscribe
Filtered by product Casdoor
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-38638 1 Casbin 1 Casdoor 2023-08-08 N/A 9.1 CRITICAL
Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/upload-resource.
CVE-2022-24124 1 Casbin 1 Casdoor 2022-02-28 5.0 MEDIUM 7.5 HIGH
The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organizations.