Casdoor是Casdoor开源的一个支持多种身份验证和授权协议的开源平台。 Casdoor 1.811.0及之前版本存在安全漏洞,该漏洞源于授权绕过,可能导致未经授权的访问。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | Casdoor | 1.811 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Casdoor up to 1.811.0 contains an authorization bypass caused by manipulation in HandleScim function in controllers/scim.go, letting remote attackers bypass authorization, exploit requires remote access. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-4210.yaml | POC Details |
| CVE-2025-44877 | Tenda AC9 安全漏洞 | |
| CVE-2025-44872 | Tenda AC9 安全漏洞 | |
| CVE-2025-44868 | WAVLINK WL-WN530H4 安全漏洞 | |
| CVE-2025-45800 | TOTOLINK A950RG 安全漏洞 | |
| CVE-2024-55069 | FFmpeg 安全漏洞 |
Zaproxy alias impedit expedita quisquam pariatur exercitationem. Nemo rerum eveniet dolores rem quia dignissimos.