SQL Injection Vulnerability in Jazzband Django Debug Toolbar
CVE-2021-30459

9.8CRITICAL

Key Information:

Vendor

Jazzband

Vendor
CVE Published:
14 April 2021

What is CVE-2021-30459?

The SQL Panel of the Jazzband Django Debug Toolbar is susceptible to a SQL Injection vulnerability that allows attackers to manipulate the raw_sql input field. By exploiting this issue, attackers can execute arbitrary SQL statements through the SQL explain, analyze, or select form, potentially compromising the integrity of the database. This flaw affects multiple versions of the toolbar, emphasizing the need for users to upgrade to the latest patched versions to mitigate risks.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.