This CSRF exploit in Casdoor 1.901.0 allows attackers to change any user's password without authentication. Affects all users; risks include unauthorized access and data breaches.
Exploit link = https://paste.laravel.io/64541980-4ffa-4dd5-a7ee-22a87f732cd8
Exploit link = https://paste.laravel.io/64541980-4ffa-4dd5-a7ee-22a87f732cd8