PT-2022-6345 · Casdoor · Casdoor

Govulnbot

·

Published

2022-01-22

·

Updated

2024-08-21

·

CVE-2022-24124

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Casdoor versions prior to 1.13.1
Description The query API in Casdoor has a SQL injection issue related to the field and value parameters. This is demonstrated by the "api/get-organizations" endpoint. The vulnerability may allow a remote attacker to gain unauthorized access to protected information due to inadequate protection of the SQL query structure.
Recommendations For versions prior to 1.13.1, update to version 1.13.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the query API or disabling the use of the field and value parameters in the affected endpoint until a patch is applied.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2023-00991
CVE-2022-24124
GHSA-M358-G4RP-533R
GO-2022-0303

Affected Products

Casdoor