Vulnerability GO-2022-0303
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
2 years ago
August 21, 2024 at 02:30 PM UTC
SQL Injection in Casdoor in github.com/casdoor/casdoor
v1.0.0 - v1.13.0
v1.0.0 - v1.13.0
Summary
SQL Injection in Casdoor in github.com/casdoor/casdoor
Details
SQL Injection in Casdoor in github.com/casdoor/casdoor
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
2 months ago
Casdoor: Arbitrary file write possible through Local File System storage provider in github.com/casdoor/casdoor
v1.0.0 - v1.1000.0 GO-2026-5945
v1.0.0 - v1.1000.0 GO-2026-5945
Unknown
2 months ago
Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature check in github.com/casdoor/casdoor
v1.0.0 - v1.1000.0 GO-2026-5953
v1.0.0 - v1.1000.0 GO-2026-5953
Unknown
3 months ago
Casdoor doesn't verify that a JWT used for token exchange is still active in github.com/casdoor/casdoor
v1.0.0 - v1.1000.0 GO-2026-5892
v1.0.0 - v1.1000.0 GO-2026-5892
Unknown
3 months ago
Casdoor does not validate the AudienceRestriction element in SAML assertions in github.com/casdoor/casdoor
v1.0.0 - v1.1000.0 GO-2026-5894
v1.0.0 - v1.1000.0 GO-2026-5894
Unknown
3 months ago
Casdoor has an authentication bypass in github.com/casdoor/casdoor
v1.0.0 - v1.1000.0 GO-2026-5895
v1.0.0 - v1.1000.0 GO-2026-5895
Impacted packages
Timeline
Published
2 years ago
August 21, 2024 at 02:30 PM UTC
Last Modified
1 day ago
October 04, 2026 at 11:40 AM UTC