Количество 8
Количество 8
CVE-2025-57833
An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed QuerySet.annotate() or QuerySet.alias().
CVE-2025-57833
An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed QuerySet.annotate() or QuerySet.alias().
CVE-2025-57833
An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed QuerySet.annotate() or QuerySet.alias().
CVE-2025-57833
An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12 ...
SUSE-SU-2025:03074-1
Security update for python-Django
GHSA-6w2r-r2m5-xq5w
Django is subject to SQL injection through its column aliases
BDU:2025-11748
Уязвимость функций annotate() и alias() программной платформы для веб-приложений Django, позволяющая нарушителю выполнить произвольный код
ROS-20250924-06
Множественные уязвимости python3-django
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-57833 An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed QuerySet.annotate() or QuerySet.alias(). | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
CVE-2025-57833 An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed QuerySet.annotate() or QuerySet.alias(). | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
CVE-2025-57833 An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed QuerySet.annotate() or QuerySet.alias(). | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
CVE-2025-57833 An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12 ... | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
SUSE-SU-2025:03074-1 Security update for python-Django | 0% Низкий | 3 месяца назад | ||
GHSA-6w2r-r2m5-xq5w Django is subject to SQL injection through its column aliases | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
BDU:2025-11748 Уязвимость функций annotate() и alias() программной платформы для веб-приложений Django, позволяющая нарушителю выполнить произвольный код | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
ROS-20250924-06 Множественные уязвимости python3-django | CVSS3: 7.1 | 2 месяца назад |
Уязвимостей на страницу