Lucene search

K
osvGoogleOSV:CVE-2021-35042
HistoryJul 02, 2021 - 10:15 a.m.

CVE-2021-35042

2021-07-0210:15:07
Google
osv.dev
13
cve-2021-35042
django
queryset.order_by
sql injection
web application
software

AI Score

9.8

Confidence

High

EPSS

0.003

Percentile

65.5%

Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application.