CVE 5.9 MEDIUM

CVE-2026-6815_CVE-2026-6815

5.9 / 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Description

An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path sanitization, an authenticated attacker with administrative privileges can perform a Path Traversal attack to create or overwrite arbitrary files anywhere on the host filesystem, bypassing the application's intended storage sandbox.

Basic Information

ID CVE-2026-6815
Source certcc
Published May 11, 2026 at 15:20
Modified May 13, 2026 at 12:33

Affected Product

Vendor Casdoor
Product Casdoor
Affected Versions Casdoor Casdoor 0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.