pysec-2023-192
CRITICAL CVSS 9.8 pysec
Description
Django 4.2 before 4.2.5 and 3.2 before 3.2.22 are affected by a potential SQL injection via certain aggregate functions.
Timeline
- Published
- 2023-10-04 12:00 UTC
- Last Modified
- 2023-11-01
CVSS Details
CVSS details not available.
Affected Products
No product information available.
CVSS metrics
| Version | Base | Severity | Vector | Exploitability | Impact | Source |
|---|---|---|---|---|---|---|
| 3.1 | 9.8 | CRITICAL | |
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cvss": 9.8,
"datePublished": "2023-10-04T12:00:00Z",
"dateUpdated": "2023-11-01T18:00:00Z",
"description": "Django 4.2 before 4.2.5 and 3.2 before 3.2.22 are affected by a potential SQL injection via certain aggregate functions.",
"id": "PYSEC-2023-192",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"version": "3.1"
}
}
]
},
"severity": "CRITICAL",
"source": "pysec",
"title": "PySec: Django SQL Injection via Aggregates"
}