Impact
A non‑global organization administrator in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant due to a mismatch between authorization based on the query id parameter and the action dictated by the request body. This flaw permits a privileged user to execute operations across tenant boundaries, potentially leading to unauthorized data loss, tampering, or denial of service. The vulnerability stems from improper authorization checks and enables a single privileged role to manipulate resources beyond its intended scope.
Affected Systems
The Casdoor application is affected. No specific version information is provided, so all installations of Casdoor that have not applied a fix remain vulnerable until a patch is released.
Risk and Exploitability
The EPSS score is below 1%, indicating a low probability of exploitation at this time, and the vulnerability is not yet listed in the CISA KEV catalog. Nevertheless, the impact of the flaw is high; any attacker who can act as a non‑global organization administrator can gain full control over resources in all tenants. The likely attack vector is via Casdoor’s web API endpoints where an attacker submits a request with a manipulated id parameter and a body specifying operations on another tenant’s resources. Because the flaw requires the user to hold at least non‑global admin rights, the system is susceptible only to insiders or compromised privileged accounts.
OpenCVE Enrichment