PT-2024-7519 · Unknown · Python-Sql

·

CVE-2024-9774

·

Published

2024-09-24

·

Updated

2026-07-07

CVSS v2.0

8.0

High

VectorAV:N/AC:L/Au:S/C:C/I:P/A:P
Name of the Vulnerable Software and Affected Versions python-sql (affected versions not specified)
Description A vulnerability was found in python-sql where unary operators do not escape non-Expression, such as And and Or. This makes any system exposing those vulnerable to an SQL injection attack, allowing a remote attacker to execute arbitrary SQL code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-08916
CVE-2024-9774
DLA-3932-1
DSA-5795-1
GHSA-PQ9P-PC3P-9HM4
OPENSUSE-SU-2024:0412-1
OPENSUSE-SU-2024:0413-1
PYSEC-2026-1855

Affected Products

Python-Sql