Executive brief
Casdoor, an open-source identity and access management platform, contains a security flaw that allows administrators of one organization to access and modify settings for other organizations. By simply entering specific web addresses, an attacker with limited administrative rights can change security configurations, set universal passwords to take over any account, or disable login services entirely. This could lead to a total system takeover or a complete shutdown of authentication services for all users.
Technical details
An improper authorization vulnerability (CWE-285) exists in Casdoor versions up to and including v2.62.0. The vulnerability stems from a lack of server-side permission validation in the organization and application editing interfaces. While the front-end UI hides unauthorized options, the back-end fails to verify if the authenticated requester has authority over the specific organization or application ID provided in the URL. A remote authenticated attacker with 'administrator' privileges for any single organization can exploit this by manually constructing URLs to modify configurations of other organizations. This can be used to set universal passwords, change OAuth redirection targets, or cause a denial of service by clearing application configurations. The issue was addressed in version 2.63.0 by improving the 'authz_filter' logic.
Affected products
- Casdoor Casdoor <= v2.62.0
Timeline
- 2025-09-18: patched: Fix released in version 2.63.0
- 2025-10-08: disclosed: Public disclosure and CVE assignment