CVE-2022-24124: SQL Injection
Published Jan 29, 2022
·Updated
The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organizations.
Affected Software
1 affected component
Casbin Casdoor<1.13.1
Remediation
Patch Available
Patch Available
Event History
Jan 29, 2022
CVE Published
via MITRE·10:53 PM
Data Sourced
via MITRE·10:53 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-24124?
CVE-2022-24124 is classified as a critical severity vulnerability due to its SQL injection nature.
2
How do I fix CVE-2022-24124?
To fix CVE-2022-24124, update Casdoor to version 1.13.1 or later.
3
What types of parameters are affected by CVE-2022-24124?
CVE-2022-24124 affects the field and value parameters in the query API.
4
What software is impacted by CVE-2022-24124?
CVE-2022-24124 impacts Casdoor versions prior to 1.13.1.
5
What kind of attack does CVE-2022-24124 enable?
CVE-2022-24124 enables SQL injection attacks, allowing unauthorized database access.