CVE-2021-30459
Summary
| CVE | CVE-2021-30459 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-14 18:15:00 UTC |
| Updated | 2021-04-21 15:05:00 UTC |
| Description | A SQL Injection issue in the SQL Panel in Jazzband Django Debug Toolbar before 1.11.1, 2.x before 2.2.1, and 3.x before 3.2.1 allows attackers to execute SQL statements by changing the raw_sql input field of the SQL explain, analyze, or select form. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Django Debug Toolbar security releases issued: 3.2.1, 2.2.1 and 1.11.1. | Weblog | Django |
CONFIRM |
www.djangoproject.com |
|
| Releases · jazzband/django-debug-toolbar · GitHub |
MISC |
github.com |
|
| SQL Injection via Select, Explain and Analyze forms of the SQLPanel for Django Debug Toolbar >= 0.10.0 · Advisory · jazzband/django-debug-toolbar · GitHub |
CONFIRM |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982752 Python (pip) Security Update for django-debug-toolbar (GHSA-pghf-347x-c2gj)