CyberRota Analysis
AI-GeneratedA high-severity vulnerability in Casdoor versions up to 4.0.0 affects the upload-resource API, allowing for missing authentication in an unknown function within the controllers/resource.go file. This flaw can be exploited remotely, posing a significant risk to systems utilizing this component. Organizations using Casdoor should prioritize immediate remediation efforts to mitigate potential unauthorized access and data breaches.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability has been found in Casdoor up to 4.0.0. This affects an unknown function of the file controllers/resource.go of the component upload-resource API. Such manipulation leads to missing authentication. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor deleted the GitHub issue for this vulnerability without any explanation. Afterwards the vendor was contacted early about this disclosure via email but did not respond in any way.