GITHUBEXPLOIT 5.4 MEDIUM

Exploit for SQL Injection in Djangoproject Django_8BEE39A6-841F-5844-893C-47BC6DC07F18

5.4 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Description

CVE-2026-1207 Django GIS RasterField SQL 注入漏洞复现 漏洞概述 漏洞类型: SQL 注入 SQL Injection 影响组件: django.contrib.gis RasterField 当使用 Django GIS 的 RasterField 进行查询时,band 参数被直接拼接到 SQL 语句中,导致 SQL 注入漏洞。攻击者可通过构造恶意的 band 参数值,注入任意 SQL 代码。 项目结构 CVE-2026-1207/ ├──...
Visit Original Source

Basic Information

ID 8BEE39A6-841F-5844-893C-47BC6DC07F18
Published Apr 26, 2026 at 02:54
Modified Apr 26, 2026 at 03:12

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.