Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35090
HistoryApr 13, 2022 - 4:28 p.m.

SQL Injection

2022-04-1316:28:39
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.003 Low

EPSS

Percentile

70.6%

django is vulnerable to SQL Injection. The vulnerability exists due to a lack of sanitization of input via the QuerySet.explain() allowing an attacker to inject malicious query via the **options argument.