{"api_version":"1","generated_at":"2026-07-23T15:43:13+00:00","cve":"CVE-2021-30459","urls":{"html":"https://cve.report/CVE-2021-30459","api":"https://cve.report/api/cve/CVE-2021-30459.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-30459","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-30459"},"summary":{"title":"CVE-2021-30459","description":"A SQL Injection issue in the SQL Panel in Jazzband Django Debug Toolbar before 1.11.1, 2.x before 2.2.1, and 3.x before 3.2.1 allows attackers to execute SQL statements by changing the raw_sql input field of the SQL explain, analyze, or select form.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-04-14 18:15:00","updated_at":"2021-04-21 15:05:00"},"problem_types":["CWE-89"],"metrics":[],"references":[{"url":"https://www.djangoproject.com/weblog/2021/apr/14/debug-toolbar-security-releases/","name":"https://www.djangoproject.com/weblog/2021/apr/14/debug-toolbar-security-releases/","refsource":"CONFIRM","tags":[],"title":"Django Debug Toolbar security releases issued: 3.2.1, 2.2.1 and 1.11.1. | Weblog | Django","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/jazzband/django-debug-toolbar/releases","name":"https://github.com/jazzband/django-debug-toolbar/releases","refsource":"MISC","tags":[],"title":"Releases · jazzband/django-debug-toolbar · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/jazzband/django-debug-toolbar/security/advisories/GHSA-pghf-347x-c2gj","name":"https://github.com/jazzband/django-debug-toolbar/security/advisories/GHSA-pghf-347x-c2gj","refsource":"CONFIRM","tags":[],"title":"SQL Injection via Select, Explain and Analyze forms of the SQLPanel for Django Debug Toolbar >= 0.10.0 · Advisory · jazzband/django-debug-toolbar · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-30459","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-30459","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"30459","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"jazzband","cpe5":"django_debug_toolbar","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-30459","qid":"982752","title":"Python (pip) Security Update for django-debug-toolbar (GHSA-pghf-347x-c2gj)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-30459","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A SQL Injection issue in the SQL Panel in Jazzband Django Debug Toolbar before 1.11.1, 2.x before 2.2.1, and 3.x before 3.2.1 allows attackers to execute SQL statements by changing the raw_sql input field of the SQL explain, analyze, or select form."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/jazzband/django-debug-toolbar/releases","refsource":"MISC","name":"https://github.com/jazzband/django-debug-toolbar/releases"},{"refsource":"CONFIRM","name":"https://github.com/jazzband/django-debug-toolbar/security/advisories/GHSA-pghf-347x-c2gj","url":"https://github.com/jazzband/django-debug-toolbar/security/advisories/GHSA-pghf-347x-c2gj"},{"refsource":"CONFIRM","name":"https://www.djangoproject.com/weblog/2021/apr/14/debug-toolbar-security-releases/","url":"https://www.djangoproject.com/weblog/2021/apr/14/debug-toolbar-security-releases/"}]}},"nvd":{"publishedDate":"2021-04-14 18:15:00","lastModifiedDate":"2021-04-21 15:05:00","problem_types":["CWE-89"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:jazzband:django_debug_toolbar:*:*:*:*:*:*:*:*","versionStartIncluding":"3.0.0","versionEndExcluding":"3.2.1","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:jazzband:django_debug_toolbar:*:*:*:*:*:*:*:*","versionStartIncluding":"2.0.0","versionEndExcluding":"2.2.1","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:jazzband:django_debug_toolbar:*:*:*:*:*:*:*:*","versionStartIncluding":"0.10.0","versionEndExcluding":"1.11.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"30459","Ordinal":"205714","Title":"CVE-2021-30459","CVE":"CVE-2021-30459","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"30459","Ordinal":"1","NoteData":"A SQL Injection issue in the SQL Panel in Jazzband Django Debug Toolbar before 1.11.1, 2.x before 2.2.1, and 3.x before 3.2.1 allows attackers to execute SQL statements by changing the raw_sql input field of the SQL explain, analyze, or select form.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"30459","Ordinal":"2","NoteData":"2021-04-14","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"30459","Ordinal":"3","NoteData":"2021-04-14","Type":"Other","Title":"Modified"}]}}}