Vendor
Casdoor versions up to 4.0.0 contain an authentication bypass vulnerability in the upload-resource API that permits remote, unauthenticated file operations.