PT-2022-27342 · Casdoor · Casdoor

Gregxsunday

·

Published

2022-12-07

·

Updated

2025-04-23

·

CVE-2022-44942

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Casdoor versions prior to 1.126.1
Description The issue is related to an arbitrary file deletion vulnerability. This vulnerability can be exploited via the uploadFile function.
Recommendations For versions prior to 1.126.1, update to version 1.126.1 or later to resolve the issue. As a temporary workaround, consider disabling the uploadFile function until a patch is available.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-44942
GHSA-F93F-55C2-8C89
GO-2022-1153

Affected Products

Casdoor