CVE-2021-30459

A SQL Injection issue in the SQL Panel in Jazzband Django Debug Toolbar before 1.11.1, 2.x before 2.2.1, and 3.x before 3.2.1 allows attackers to execute SQL statements by changing the raw_sql input field of the SQL explain, analyze, or select form.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:jazzband:django_debug_toolbar:*:*:*:*:*:*:*:*
cpe:2.3:a:jazzband:django_debug_toolbar:*:*:*:*:*:*:*:*
cpe:2.3:a:jazzband:django_debug_toolbar:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:03

Type Values Removed Values Added
References () https://github.com/jazzband/django-debug-toolbar/releases - Third Party Advisory () https://github.com/jazzband/django-debug-toolbar/releases - Third Party Advisory
References () https://github.com/jazzband/django-debug-toolbar/security/advisories/GHSA-pghf-347x-c2gj - Patch, Third Party Advisory () https://github.com/jazzband/django-debug-toolbar/security/advisories/GHSA-pghf-347x-c2gj - Patch, Third Party Advisory
References () https://www.djangoproject.com/weblog/2021/apr/14/debug-toolbar-security-releases/ - Vendor Advisory () https://www.djangoproject.com/weblog/2021/apr/14/debug-toolbar-security-releases/ - Vendor Advisory

Information

Published : 2021-04-14 18:15

Updated : 2024-11-21 06:03


NVD link : CVE-2021-30459

Mitre link : CVE-2021-30459

CVE.ORG link : CVE-2021-30459


JSON object : View

Products Affected

jazzband

  • django_debug_toolbar
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')