PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 14, 2026

Casdoor - Authorization Bypass

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsurl
CostFree
2.4k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
6.9
CVSSmedium
Exploitable remotely over the internet · no authentication required.
Description

A vulnerability classified as critical was found in Casdoor up to 1.811.0. This vulnerability affects the function HandleScim of the file controllers/scim.go of the component SCIM User Creation Endpoint. The manipulation leads to authorization bypass. The attack can be initiated remotely. Upgrading to version 1.812.0 is able to address this issue. The name of the patch is 3d12ac8dc2282369296c3386815c00a06c6a92fe. It is recommended to upgrade the affected component.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Casdoorby n/a
1.811
Updated Sep 18, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

Casdoor - Authorization Bypass CVE-2025-4210 Scanner | S4E