PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2025-4210

6.9
CVSSmedium
Exploitable remotely over the internet · no authentication required.
Description

A vulnerability classified as critical was found in Casdoor up to 1.811.0. This vulnerability affects the function HandleScim of the file controllers/scim.go of the component SCIM User Creation Endpoint. The manipulation leads to authorization bypass. The attack can be initiated remotely. Upgrading to version 1.812.0 is able to address this issue. The name of the patch is 3d12ac8dc2282369296c3386815c00a06c6a92fe. It is recommended to upgrade the affected component.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
casdoor
Updated Sep 18, 2026View on NVD →
S4E scanner

Casdoor - Authorization Bypass

Casdoor up to 1.811.0 contains an authorization bypass caused by manipulation in HandleScim function in controllers/scim.go, letting remote attackers bypass authorization, exploit requires remote access. References: https://github.com/casdoor/casdoor/commit/3d12ac8dc2282369296c3386815c00a06c6a92fe https://nvd.nist.gov/vuln/detail/CVE-2025-4210 Remediation: Upgrade to version 1.812.0.

Used 2.4k times · url

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →