Casdoor up to 1.811.0 contains an authorization bypass caused by manipulation in HandleScim function in controllers/scim.go, letting remote attackers bypass authorization, exploit requires remote access.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view