Vulnerability GHSA-9vm3-r8gq-cr6x
Critical
CRITICAL RISK
CVSS Score: 9.1
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
4 years ago
September 10, 2022 at 12:00 AM UTC
Casdoor arbitrary file write vulnerability
v1.0.0 - v1.103.0
v1.0.0 - v1.103.0
Summary
Casdoor arbitrary file write vulnerability
Details
Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/upload-resource.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
2 months ago
Casdoor: Arbitrary file write possible through Local File System storage provider in github.com/casdoor/casdoor
v1.0.0 - v1.1000.0 GO-2026-5945
v1.0.0 - v1.1000.0 GO-2026-5945
Unknown
2 months ago
Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature check in github.com/casdoor/casdoor
v1.0.0 - v1.1000.0 GO-2026-5953
v1.0.0 - v1.1000.0 GO-2026-5953
Unknown
3 months ago
Casdoor doesn't verify that a JWT used for token exchange is still active in github.com/casdoor/casdoor
v1.0.0 - v1.1000.0 GO-2026-5892
v1.0.0 - v1.1000.0 GO-2026-5892
Unknown
3 months ago
Casdoor does not validate the AudienceRestriction element in SAML assertions in github.com/casdoor/casdoor
v1.0.0 - v1.1000.0 GO-2026-5894
v1.0.0 - v1.1000.0 GO-2026-5894
Unknown
3 months ago
Casdoor has an authentication bypass in github.com/casdoor/casdoor
v1.0.0 - v1.1000.0 GO-2026-5895
v1.0.0 - v1.1000.0 GO-2026-5895
Impacted packages
Timeline
Published
4 years ago
September 10, 2022 at 12:00 AM UTC
Last Modified
1 day ago
October 04, 2026 at 11:40 AM UTC