/DjVul_StringAgg

Django StringAgg SQL Injection (CVE-2020-7471)

Primary LanguagePython

Django CVE-2020-7471 SQLi

CVE-2020-7471: Potential SQL injection via StringAgg(delimiter) django.contrib.postgres.aggregates.StringAgg aggregation function was subject to SQL injection, using a suitably crafted delimiter.

RUN

python manage.py makemigrations

python manage.py migrate

python manage.py runserver

参考