Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5m9m-j5p7-m7f9

Опубликовано: 08 окт. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.2

Описание

Casdoor is vulnerable to Improper Authorization

An issue in the permission verification module and organization/application editing interface in Casdoor before 2.63.0 allows remote authenticated administrators of any organization within the system to bypass the system's permission verification mechanism by directly concatenating URLs after login.

Пакеты

Наименование

github.com/casdoor/casdoor

go
Затронутые версииВерсия исправления

< 2.63.0

2.63.0

EPSS

Процентиль: 20%
0.00063
Низкий

7.2 High

CVSS3

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 7.2
nvd
4 месяца назад

An issue in the permission verification module and organization/application editing interface in Casdoor v2.26.0 and before, and fixed in v.2.63.0, allows remote authenticated administrators of any organization within the system to bypass the system's permission verification mechanism by directly concatenating URLs after login

EPSS

Процентиль: 20%
0.00063
Низкий

7.2 High

CVSS3

Дефекты

CWE-285