Vulnerability GHSA-m358-g4rp-533r
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
4 years ago
February 01, 2022 at 12:49 AM UTC
SQL Injection in Casdoor
v1.0.0 - v1.13.0
v1.0.0 - v1.13.0
Summary
SQL Injection in Casdoor
Details
The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organizations.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
2 months ago
Casdoor: Arbitrary file write possible through Local File System storage provider in github.com/casdoor/casdoor
v1.0.0 - v1.1000.0 GO-2026-5945
v1.0.0 - v1.1000.0 GO-2026-5945
Unknown
2 months ago
Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature check in github.com/casdoor/casdoor
v1.0.0 - v1.1000.0 GO-2026-5953
v1.0.0 - v1.1000.0 GO-2026-5953
Unknown
3 months ago
Casdoor doesn't verify that a JWT used for token exchange is still active in github.com/casdoor/casdoor
v1.0.0 - v1.1000.0 GO-2026-5892
v1.0.0 - v1.1000.0 GO-2026-5892
Unknown
3 months ago
Casdoor does not validate the AudienceRestriction element in SAML assertions in github.com/casdoor/casdoor
v1.0.0 - v1.1000.0 GO-2026-5894
v1.0.0 - v1.1000.0 GO-2026-5894
Unknown
3 months ago
Casdoor has an authentication bypass in github.com/casdoor/casdoor
v1.0.0 - v1.1000.0 GO-2026-5895
v1.0.0 - v1.1000.0 GO-2026-5895
Impacted packages
Timeline
Published
4 years ago
February 01, 2022 at 12:49 AM UTC
Last Modified
1 day ago
October 04, 2026 at 11:40 AM UTC