Permission Bypass in Casdoor Impacting Organization Editing Interface
CVE-2025-61524
7.2HIGH
What is CVE-2025-61524?
A vulnerability exists in Casdoor's permission verification module and organization/application editing interface, allowing remote authenticated administrators to circumvent the permission checks. By manipulating URLs after logging in, these administrators can gain unauthorized access to functionalities, potentially leading to security breaches and compromising system integrity. Users of Casdoor versions prior to 2.26.0 should take immediate precautions to mitigate this risk.
