PatchSiren cyber security CVE debrief
CVE-2026-5468 Casdoor CVE debrief
A security flaw has been discovered in Casdoor 2.356.0, affecting the function dangerouslySetInnerHTML. Performing a manipulation of the argument formCss/formCssMobile/formSideHtml results in cross site scripting. The attack can be initiated remotely. This vulnerability has a CVSS score of 2 and is considered Low severity. Users of Casdoor 2.356.0 should be aware of this cross site scripting vulnerability and take necessary precautions.
- Vendor
- Casdoor
- Product
- Casdoor
- CVSS
- LOW 2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-03
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-03
- Advisory updated
- 2026-07-24
Who should care
Users of Casdoor 2.356.0 should be aware of this cross site scripting vulnerability and take necessary precautions. Operators of affected systems should review the vulnerability details and plan for mitigations or updates. Security teams should monitor for suspicious activity and exception tracking. Vulnerability management teams should prioritize patching or mitigating this vulnerability.
Technical summary
The vulnerability is located in the dangerouslySetInnerHTML function of Casdoor 2.356.0. An attacker can perform a manipulation of the argument formCss/formCssMobile/formSideHtml to execute cross site scripting attacks remotely. The CVSS score of 2 indicates a Low severity vulnerability. The vendor was contacted early about this disclosure but did not respond in any way. This cross-site scripting vulnerability allows remote attackers to inject malicious scripts into the application, potentially leading to unauthorized actions or data breaches. Users of Casdoor 2.356.0 should be aware of this vulnerability and take necessary precautions to protect their systems. It is essential to review the vulnerability details and plan for mitigations or updates. Security teams should monitor for suspicious activity and exception tracking to detect potential attacks.
Defensive priority
Low priority due to CVSS score of 2 and low severity.
Recommended defensive actions
- Inventory and verify affected Casdoor installations
- Apply vendor patches or updates if available
- Implement compensating controls such as input validation and output encoding
- Monitor for suspicious activity and exception tracking
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record was published on 2026-04-03T14:16:33.837Z and last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Analyzed. The source details are limited, and defenders should verify the affected scope and severity with the vendor or other trusted sources. The vulnerability affects Casdoor 2.356.0, and the attack can be initiated remotely.
Official resources
-
CVE-2026-5468 CVE record
CVE.org
-
CVE-2026-5468 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Third Party Advisory, VDB Entry
-
Mitigation or vendor reference
[email protected] - Third Party Advisory, VDB Entry
-
Source reference
[email protected] - Permissions Required, VDB Entry
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-03T14:16:33.837Z and has not been modified since then. The NVD entry is currently Analyzed.