References https://nvd.nist.gov/vuln/detail/CVE-2022-24124 https://github.com/casdoor/casdoor/issues/439 https://github.com/casdoor/casdoor/pull/442 https://github.com/casdoor/casdoor/compare/v1.13.0...v1.13.1 https://github.com/advisories/GHSA-m358-g4rp-533r https://github.com/ColdFusionX/CVE-2022-24124 https://www.exploit-db.com/exploits/50792 https://packetstormsecurity.com/files/166163/Casdoor-1.13.0-SQL-Injection.html https://blog.qualys.com/vulnerabilities-threat-research/2022/03/09/casdoor-sql-injection-cve-2022-24124 https://www.sentinelone.com/vulnerability-database/cve-2022-24124/
Related VulnerabilitiesCasdoor /conf/app.conf 信息泄露漏洞(CVE-2024-5587)PoCcasdoor-default-login: Casdoor - Default Admin CredentialsCasdoor /api/login 默认口令漏洞PoCCVE-2025-4210: Casdoor - Authorization BypassPoCCVE-2022-24124: Casdoor 1.13.0 - Unauthenticated SQL InjectionPoCcasdoor-static-fileread: Casdoor 任意文件读取漏洞PoCcasdoor-unauth-operations: Casdoor <=v1.811.0 - Unauthenticated SCIM OperationsPoCcasdoor-users-password: Casdoor get-users Account Password DisclosureCasdoor /static 文件读取漏洞Casbin casdoor static 任意文件读取漏洞Casdoor系统存在信息泄露