{"id":"CVE-2022-24124","aliases":["PYSEC-2022-43189","GHSA-m358-g4rp-533r","GO-2022-0303"],"title":"The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by ap…","summary":"The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organizations.","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","vendor":"casdoor","product":"casdoor","ecosystem":"pip","affected":["casdoor < 1.13.1"],"patched":["casdoor 1.13.1"],"published":"2022-01-29","updated":"2026-10-04","sourceUpdated":"2026-10-04T11:40:45.650201142Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/PYSEC-2022-43189","references":[{"url":"https://github.com/casdoor/casdoor/compare/v1.13.0...v1.13.1"},{"url":"https://github.com/casdoor/casdoor/issues/439"},{"url":"https://github.com/casdoor/casdoor/pull/442"},{"url":"http://packetstormsecurity.com/files/166163/Casdoor-1.13.0-SQL-Injection.html"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24124"},{"url":"https://github.com/casdoor/casdoor/commit/5ec0c7a89005819960d8fe07f5ddda13d1371b8c"},{"url":"https://github.com/casdoor/casdoor"},{"url":"https://github.com/advisories/GHSA-m358-g4rp-533r"}],"tags":["osv","pip","go","exploit-available"],"epss":0.55295,"epssPercentile":0.99007,"exploits":{"exploitdb":true,"github":3,"githubRepos":["https://github.com/ColdFusionX/CVE-2022-24124","https://github.com/abbarhissarh/CVE-2022-24124","https://github.com/b1gdog/CVE-2022-24124"],"nuclei":["CVE-2022-24124"],"checkedAt":"2026-10-05T07:28:57.922Z"},"exploitAvailable":true,"ingestedAt":"2026-10-05T07:28:24.383Z","slug":"CVE-2022-24124","body":"## Overview\n\nThe query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organizations.\n\n## Affected packages\n\n- `casdoor < 1.13.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `casdoor 1.13.1`","depth":"midnight","depthScore":64,"depthScoreParts":{"impact":41.3,"likelihood":11.1,"exploitation":12,"ransomware":0},"changes":[]}