PT-2022-24495 · Casdoor · Casdoor

Published

2022-09-09

·

Updated

2024-08-21

·

CVE-2022-38638

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Casdoor version 1.97.3
Description The issue is related to an arbitrary file write vulnerability. This vulnerability can be exploited via the fullFilePath parameter at the "/api/upload-resource" API endpoint.
Recommendations For Casdoor version 1.97.3, as a temporary workaround, consider restricting access to the "/api/upload-resource" API endpoint until a patch is available. Avoid using the fullFilePath parameter in this endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-38638
GHSA-9VM3-R8GQ-CR6X
GO-2022-1006

Affected Products

Casdoor