PT-2024-7519 · Unknown · Python-Sql

Cédric Krier

·

Published

2024-09-24

·

Updated

2025-02-07

·

CVE-2024-9774

CVSS v2.0

8.0

High

VectorAV:N/AC:L/Au:S/C:C/I:P/A:P
Name of the Vulnerable Software and Affected Versions python-sql (affected versions not specified)
Description A vulnerability was found in python-sql where unary operators do not escape non-Expression, such as And and Or. This makes any system exposing those vulnerable to an SQL injection attack, allowing a remote attacker to execute arbitrary SQL code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2024-08916
CVE-2024-9774
DLA-3932-1
DSA-5795-1
GHSA-PQ9P-PC3P-9HM4
OPENSUSE-SU-2024:0412-1
OPENSUSE-SU-2024:0413-1

Affected Products

Python-Sql