Cross-site request forgery in nginx-ui - #VU142581
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to authenticate a victim\'s browser as the attacker\'s account and disclose sensitive information.
The vulnerability exists due to improper authentication in the Casdoor SSO callback flow when handling OAuth callback requests. A remote attacker can submit a crafted authorization code and state value to authenticate the victim as the attacker\'s account and disclose sensitive information.
User interaction is required to visit an attacker-controlled page that submits the callback request.