Authorization Bypass Vulnerability in Casdoor Affecting SCIM User Creation Endpoint
CVE-2025-4210
What is CVE-2025-4210?
A vulnerability affecting the SCIM User Creation Endpoint in Casdoor versions up to 1.811.0 allows an attacker to bypass authorization controls. This issue can be exploited remotely, potentially granting unauthorized access to sensitive functionalities. The vulnerable function, HandleScim, located in the file controllers/scim.go, fails to properly validate permissions for user creation operations. Users are advised to upgrade to version 1.812.0, which includes a patch addressing this vulnerability (commit 3d12ac8dc2282369296c3386815c00a06c6a92fe).

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Casdoor 1.811
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
