漏洞描述 Casdoor 是 Casbin 开源社区推出的基于 OAuth 2.0 / OIDC 的中心化的单点登录(SSO)身份验证平台。 Casdoor static 存在任意文件读取漏洞,攻击者通过发送特殊的请求包可以获取服务器中的敏感文件。
相关漏洞推荐 智联云采 SRM2.0 /adpweb/static/..;/a/db/dbBackupScheme/restore 命令执行漏洞 lsfusion /file/static/noauth 目录遍历漏洞(CVE-2025-13261) 智互联-SRM /adpweb/static/..;/api/authority/getUser 信息泄露漏洞 POC CVE-2022-24124: Casdoor 1.13.0 - Unauthenticated SQL Injection POC CVE-2022-24124: Casdoor 1.13.0 - Unauthenticated SQL Injection POC azure-storage-static-website-review: Azure Storage Static Website Configuration Review POC casbin-get-users-account-password-disclosure: Casbin get-users 账号密码泄漏漏洞 POC casdoor-static-fileread: Casdoor 任意文件读取漏洞 POC gcloud-nat-static-ip-unconfigured: Cloud NAT Gateways Not Configured with Reserved Static IPs POC gcloud-vpc-unattached-static-ips: Unattached Static External IP Addresses POC gstatic-angular-csp-bypass: Content-Security-Policy Bypass - GStatic Angular POC gstatic-recaptcha-csp-bypass: Content-Security-Policy Bypass - GStatic reCAPTCHA POC gstatic-ssl-csp-bypass: Content-Security-Policy Bypass - GStatic SSL