Skip to content

secoba/DjVul_StringAgg

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

1 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Django CVE-2020-7471 SQLi

CVE-2020-7471: Potential SQL injection via StringAgg(delimiter) django.contrib.postgres.aggregates.StringAgg aggregation function was subject to SQL injection, using a suitably crafted delimiter.

RUN

python manage.py makemigrations

python manage.py migrate

python manage.py runserver

参考

About

Django StringAgg SQL Injection (CVE-2020-7471)

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages