Wiz Agents & Workflows are here

CVE-2025-61524
vulnerability analysis and mitigation

Overview

An issue in the permission verification module and organization/application editing interface in Casdoor v2.26.0 and before, and fixed in v.2.63.0, allows remote authenticated administrators of any organization within the system to bypass the system's permission verification mechanism by directly concatenating URLs after login (NVD, Casdoor Commit).

Technical details

The vulnerability exists due to Casdoor only controlling access rights at the front-end interface level while lacking strict permission checking at the back-end interface level. The system fails to perform secondary verification of organizational rights when processing application configuration saving requests. This allows attackers to bypass front-end restrictions by constructing URLs directly to obtain unauthorized access. The vulnerability has been assigned a CVSS v3.1 Base Score of 7.2 (HIGH) with vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H (Security Advisory).

Impact

The vulnerability can lead to multiple severe impacts: 1) Denial-of-service attacks by clearing configurations of any application, preventing user logins, 2) Privilege escalation by modifying universal passwords of other organizations, enabling access to any account including system administrator accounts, 3) Information leakage and hijacking through modification of OAuth client credentials and redirect URLs (Security Advisory).

Mitigation and workarounds

The vulnerability has been fixed in Casdoor version 2.63.0. Organizations running affected versions should immediately upgrade to version 2.63.0 or later. The fix includes improvements to the authorization filter system to properly verify permissions at both frontend and backend levels (Casdoor Release).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management