CVE-2025-61524: High severity Casdoor Casdoor vulnerability
An issue in the permission verification module and organization/application editing interface in Casdoor before 2.63.0 allows remote authenticated administrators of any organization within the system to bypass the system's permission verification mechanism by directly concatenating URLs after login.
Other sources
An issue in the permission verification module and organization/application editing interface in Casdoor v2.26.0 and before, and fixed in v.2.63.0, allows remote authenticated administrators of any organization within the system to bypass the system's permission verification mechanism by directly concatenating URLs after login
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/casdoor/casdoorto a version that resolves this vulnerability.Fixed in 2.63.0 - Upgrade
Upgrade
Casdoorto a version that resolves this vulnerability.Fixed in 2.63.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61524?
CVE-2025-61524 has a medium severity rating due to its impact on permission verification allowing unauthorized access.
How do I fix CVE-2025-61524?
To fix CVE-2025-61524, upgrade to Casdoor version 2.63.0 or later.
Who is affected by CVE-2025-61524?
CVE-2025-61524 affects remote authenticated administrators of any organization using Casdoor versions before 2.63.0.
What are the potential consequences of CVE-2025-61524?
The potential consequences of CVE-2025-61524 include unauthorized access to sensitive organization/application settings.
Is CVE-2025-61524 an exploit or an information disclosure?
CVE-2025-61524 is classified as an exploit that allows bypassing of permission verification mechanisms.