Description
The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organizations.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-m358-g4rp-533r | SQL Injection in Casdoor |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T03:59:23.921Z
Reserved: 2022-01-29T00:00:00.000Z
Link: CVE-2022-24124
No data.
Status : Modified
Published: 2022-01-29T23:15:07.540
Modified: 2024-11-21T06:49:51.500
Link: CVE-2022-24124
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA