Lucene search

K
osvGoogleOSV:GHSA-PGHF-347X-C2GJ
HistoryApr 16, 2021 - 7:53 p.m.

SQL Injection via in django-debug-toolbar

2021-04-1619:53:28
Google
osv.dev
12

0.002 Low

EPSS

Percentile

56.6%

Impact

With Django Debug Toolbar attackers are able to execute SQL by changing the raw_sql input of the SQL explain, analyze or select forms and submitting the form.

NOTE: This is a high severity issue for anyone using the toolbar in aproduction environment.

Generally the Django Debug Toolbar team only maintains the latest version of django-debug-toolbar, but an exception was made because of the high severity of this issue.

Patches

Please upgrade to one of the following versions, depending on the major version you’re using:

For more information

If you have any questions or comments about this advisory:

0.002 Low

EPSS

Percentile

56.6%

Related for OSV:GHSA-PGHF-347X-C2GJ