Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password. This vulnerability allows attackers to arbitrarily change the victim user's password via supplying a crafted URL.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-34927.json"