CVE-2021-30459
Last modified
CVE-2021-30459 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A SQL Injection issue in the SQL Panel in Jazzband Django Debug Toolbar before 1.11.1, 2.x before 2.2.1, and 3.x before 3.2.1 allows attackers to execute SQL statements by changing the raw_sql input field of the SQL explain, analyze, or select form.. EPSS estimates a 1.93% chance of exploitation in the next 30 days.
Description
A SQL Injection issue in the SQL Panel in Jazzband Django Debug Toolbar before 1.11.1, 2.x before 2.2.1, and 3.x before 3.2.1 allows attackers to execute SQL statements by changing the raw_sql input field of the SQL explain, analyze, or select form.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jazzband | Django Debug Toolbar | >= 0.10.0, < 1.11.1 |
| Jazzband | Django Debug Toolbar | >= 2.0.0, < 2.2.1 |
| Jazzband | Django Debug Toolbar | >= 3.0.0, < 3.2.1 |
References
- https://github.com/jazzband/django-debug-toolbar/releasesThird Party Advisory
- https://github.com/jazzband/django-debug-toolbar/security/advisories/GHSA-pghf-347x-c2gjPatch, Third Party Advisory
- https://github.com/jazzband/django-debug-toolbar/releasesThird Party Advisory
- https://github.com/jazzband/django-debug-toolbar/security/advisories/GHSA-pghf-347x-c2gjPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-30459?
How severe is CVE-2021-30459?
How do I fix CVE-2021-30459?
Are you affected by CVE-2021-30459?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
