CVE-2022-24124
HIGH NUCLEICasdoor <1.13.1 - SQL Injection
Title source: llmDescription
The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organizations.
Exploits (6)
exploitdb
WORKING POC
by Mayank Deshmukh · gowebappsmultiple
https://www.exploit-db.com/exploits/50792
Nuclei Templates (1)
Casdoor 1.13.0 - Unauthenticated SQL Injection
HIGHby cckuailong
Shodan:
http.title:"Casdoor" || http.title:"casdoor"
FOFA:
title="casdoor"
Scores
CVSS v3
7.5
EPSS
0.5738
EPSS Percentile
98.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-89
Status
published
Affected Products (2)
casbin/casdoor
< 1.13.1
casdoor/casdoor
< 1.13.1Go
Timeline
Published
Jan 29, 2022
Tracked Since
Feb 18, 2026