# CVE-2024-41657

## Summary

- **CVE ID:** CVE-2024-41657
- **Severity:** HIGH
- **CVSS Score:** 8.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N)
- **CWE:** CWE-942
- **Published:** Aug 20, 2024
- **Last Modified:** Mar 13, 2026

## Description

Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earlier, a logic vulnerability exists in the beego filter CorsFilter that allows any website to make cross domain requests to Casdoor as the logged in user. Due to the a logic error in checking only for a prefix when authenticating the Origin header, any domain can create a valid subdomain with a valid subdomain prefix (Ex: localhost.example.com), allowing the website to make requests to Casdoor as the current signed-in user.

## Affected Products

- casdoor — casdoor (<= 1.577.0)

## References

- [CNA](https://securitylab.github.com/advisories/GHSL-2024-035_GHSL-2024-036_casdoor/)
- [CNA](https://github.com/casdoor/casdoor/blob/v1.577.0/routers/cors_filter.go#L45)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.79%
- **EPSS Percentile:** 54.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._