VDB
CVE-2025-4210
CVE-2025-4210
PUBLISHED
KEV
CVSS 6.900000095367432 MEDIUM
Casdoor SCIM User Creation Endpoint scim.go HandleScim authorization in github.com/casdoor/casdoor
EPSS 1.84% · 77.7th percentile
Risk Scores
CVSS 4.0
6.900000095367432
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
EPSS Score
1.84%
77.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | Casdoor | 1.811, 1.811 |
| github.com | casdoor/casdoor | 0, 0 |
Timeline
- Aug 12, 2021 CrowdSec Sighting
- Mar 8, 2022 CrowdSec Sighting
- Mar 18, 2022 CrowdSec Sighting
- May 6, 2022 CrowdSec Sighting
- Sep 27, 2022 CrowdSec Sighting
- Dec 2, 2022 CrowdSec Sighting
- Dec 9, 2022 CrowdSec Sighting
- Dec 11, 2022 CrowdSec Sighting
- Dec 11, 2022 CrowdSec Sighting
- Dec 11, 2022 CrowdSec Sighting
- Dec 11, 2022 CrowdSec Sighting
- Dec 11, 2022 CrowdSec Sighting
References
- VDB-307180 | CTI Indicators (IOB, IOC, IOA) url
- https://github.com/casdoor/casdoor/commit/3d12ac8dc2282369296c3386815c00a06c6a92fe fix
- https://github.com/casdoor/casdoor package
- https://vuldb.com/?id.307180 url
- https://vuldb.com/?submit.556201 url
- https://github.com/casdoor/casdoor/releases/tag/v1.812.0 fix
- https://nvd.nist.gov/vuln/detail/CVE-2025-4210 advisory
- https://pkg.go.dev/vuln/GO-2024-3661 url
- Nuclei Template exploit