SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DLA-1718-1 | sqlalchemy security update |
![]() |
DLA-2811-1 | sqlalchemy security update |
![]() |
EUVD-2019-0134 | SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled. |
![]() |
GHSA-38fc-9xqv-7f7q | SQLAlchemy is vulnerable to SQL Injection via group_by parameter |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T20:54:27.873Z
Reserved: 2019-02-06T00:00:00
Link: CVE-2019-7548

No data.

Status : Modified
Published: 2019-02-06T21:29:01.063
Modified: 2024-11-21T04:48:18.397
Link: CVE-2019-7548


No data.