Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[GHSA-794h-2c6j-qp4q] SQL injection vulnerability in rating.php in New 5 star... #4451

Conversation

MarkLee131
Copy link

Updates

  • Affected products
  • References
  • Source code location
  • Summary

Comments
add 2 patches for django: django/django@594a28a
django/django@e3e992e

@github-actions github-actions bot changed the base branch from main to MarkLee131/advisory-improvement-4451 May 21, 2024 16:18
@darakian
Copy link
Contributor

@MarkLee131 was this PR created in error? It doesn't seem like it applies to django to me.

@MarkLee131
Copy link
Author

@darakian Hi, this cve was rooted in the TPL, but it caused the vulns within django. the detailed info can be accessed in https://docs.djangoproject.com/en/3.2/releases/security/#october-9-2009-cve-2009-3965.

@darakian
Copy link
Contributor

darakian commented May 22, 2024

@MarkLee131, I believe you may have actually discovered a typo in the django docs :)
I think the actual CVE is
https://nvd.nist.gov/vuln/detail/CVE-2009-3695
rather than
https://nvd.nist.gov/vuln/detail/CVE-2009-3965

We have CVE-2009-3695 in our DB as well, but thank you for raising this. I've gone ahead and shared this with the django folk, so we can see if they agree
https://code.djangoproject.com/ticket/35473#ticket

@advisory-database advisory-database bot closed this Jul 2, 2024
@github-actions github-actions bot deleted the MarkLee131-GHSA-794h-2c6j-qp4q branch July 2, 2024 20:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants