A SQL Injection issue in the SQL Panel in Jazzband Django Debug Toolbar before 1.11.1, 2.x before 2.2.1, and 3.x before 3.2.1 allows attackers to execute SQL statements by changing the raw_sql input field of the SQL explain, analyze, or select form.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0052 | A SQL Injection issue in the SQL Panel in Jazzband Django Debug Toolbar before 1.11.1, 2.x before 2.2.1, and 3.x before 3.2.1 allows attackers to execute SQL statements by changing the raw_sql input field of the SQL explain, analyze, or select form. |
Github GHSA |
GHSA-pghf-347x-c2gj | SQL Injection via in django-debug-toolbar |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T22:32:41.140Z
Reserved: 2021-04-08T00:00:00
Link: CVE-2021-30459
No data.
Status : Modified
Published: 2021-04-14T18:15:14.877
Modified: 2024-11-21T06:03:57.840
Link: CVE-2021-30459
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA