Casdoor up to 1.811.0 contains an authorization bypass caused by manipulation in HandleScim function in controllers/scim.go, letting remote attackers bypass authorization, exploit requires remote access.
id: CVE-2025-4210
info:
name: Casdoor - Authorization Bypass
author: theamanrawat
severity: h
...