The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organizations.
docker-compose up -d
Visit http://xxx:8000
Name | Name | Last commit date | ||
---|---|---|---|---|
parent directory.. | ||||
The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organizations.
docker-compose up -d
Visit http://xxx:8000