Casdoor version 1.13.0 suffers from a remote unauthenticated SQL injection vulnerability via the query API in Casdoor before 1.13.1 related to the field and value parameters, as demonstrated by api/get-organizations.
View the template here CVE-2022-24124.yaml
References:
https://github.com/cckuailong/reapoc/tree/main/2022/CVE-2022-24124/vultarget