Impact
The flaw resides in the ApiFilter function of routers/authz_filter.go in Casdoor versions up to 3.161.1, where a missing authentication check allows an attacker to use the API endpoint without providing valid credentials. This can lead to unauthorized access to protected resources and data. The vulnerability is rated CVSS 6.9 and is exploitable from a remote location with publicly available attack code.
Affected Systems
Casdoor software, specifically all installations using version 3.161.1 or earlier, may be impacted. Upgrades beyond 3.161.1 are not known to contain the fix.
Risk and Exploitability
With a CVSS score of 6.9, the vulnerability presents medium to high risk. The exploit is publicly available, and the EPSS score is currently unavailable, but the lack of a KEV listing does not mitigate the potential for widespread abuse. Attackers can initiate the exploit remotely, bypassing authentication to gain unauthorized access.
OpenCVE Enrichment