CVE-2025-61524: Casdoor is vulnerable to Improper Authorization
(updated )
An issue in the permission verification module and organization/application editing interface in Casdoor before 2.63.0 allows remote authenticated administrators of any organization within the system to bypass the system’s permission verification mechanism by directly concatenating URLs after login.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-61524 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →