---
id: CVE-2022-24124
aliases:
  - PYSEC-2022-43189
  - GHSA-m358-g4rp-533r
  - GO-2022-0303
title: >-
  The query API in Casdoor before 1.13.1 has a SQL injection vulnerability
  related to the field and value parameters, as demonstrated by ap…
summary: >-
  The query API in Casdoor before 1.13.1 has a SQL injection vulnerability
  related to the field and value parameters, as demonstrated by
  api/get-organizations.
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
vendor: casdoor
product: casdoor
ecosystem: pip
affected:
  - casdoor < 1.13.1
patched:
  - casdoor 1.13.1
published: '2022-01-29'
updated: '2026-10-04'
sourceUpdated: '2026-10-04T11:40:45.650201142Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/PYSEC-2022-43189'
references:
  - url: 'https://github.com/casdoor/casdoor/compare/v1.13.0...v1.13.1'
  - url: 'https://github.com/casdoor/casdoor/issues/439'
  - url: 'https://github.com/casdoor/casdoor/pull/442'
  - url: >-
      http://packetstormsecurity.com/files/166163/Casdoor-1.13.0-SQL-Injection.html
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2022-24124'
  - url: >-
      https://github.com/casdoor/casdoor/commit/5ec0c7a89005819960d8fe07f5ddda13d1371b8c
  - url: 'https://github.com/casdoor/casdoor'
  - url: 'https://github.com/advisories/GHSA-m358-g4rp-533r'
tags:
  - osv
  - pip
  - go
  - exploit-available
epss: 0.55295
epssPercentile: 0.99007
exploits:
  exploitdb: true
  github: 3
  githubRepos:
    - 'https://github.com/ColdFusionX/CVE-2022-24124'
    - 'https://github.com/abbarhissarh/CVE-2022-24124'
    - 'https://github.com/b1gdog/CVE-2022-24124'
  nuclei:
    - CVE-2022-24124
  checkedAt: '2026-10-05T07:28:57.922Z'
exploitAvailable: true
ingestedAt: '2026-10-05T07:28:24.383Z'
---

## Overview

The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organizations.

## Affected packages

- `casdoor < 1.13.1`

## Remediation

Upgrade to a patched release:

- `casdoor 1.13.1`
