pysec-2023-192

CRITICAL CVSS 9.8 pysec
Description

Django 4.2 before 4.2.5 and 3.2 before 3.2.22 are affected by a potential SQL injection via certain aggregate functions.

Timeline
Published
2023-10-04 12:00 UTC
Last Modified
2023-11-01
CVSS Details

CVSS details not available.

Affected Products

No product information available.

CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.1 9.8 CRITICAL
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cvss": 9.8,
  "datePublished": "2023-10-04T12:00:00Z",
  "dateUpdated": "2023-11-01T18:00:00Z",
  "description": "Django 4.2 before 4.2.5 and 3.2 before 3.2.22 are affected by a potential SQL injection via certain aggregate functions.",
  "id": "PYSEC-2023-192",
  "metrics": {
    "cvssMetricV31": [
      {
        "cvssData": {
          "baseScore": 9.8,
          "baseSeverity": "CRITICAL",
          "version": "3.1"
        }
      }
    ]
  },
  "severity": "CRITICAL",
  "source": "pysec",
  "title": "PySec: Django SQL Injection via Aggregates"
}
View JSON API Download JSON