← All CVEs

CVE-2022-34265

critical · 9.8

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name value. Applications that constrain the lookup name and kind choice to a known safe list are unaffected.

9.8
CVSS
73.3%
EPSS (exploit prob.)
99th
EPSS percentile
2022-07-04
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-89

Affected products

VendorProductAffected versions
djangoprojectdjango>= 3.2, < 3.2.14
djangoprojectdjango>= 4.0, < 4.0.6

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-34265