Description
Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a suitably crafted tolerance to GIS functions and aggregates on Oracle, it was possible to break escaping and inject malicious SQL.
Remediation
References
Related Vulnerabilities
Apache Tomcat version older than 4.1.39
WordPress Other Vulnerability (CVE-2007-0540)
Chart.js Improper Input Validation Vulnerability (CVE-2020-7746)
WordPress Plugin Simple Slide Show TimThumb Arbitrary File Upload (1.0)
WordPress Plugin Ldap WP Login/Active Directory Integration Multiple Vulnerabilities (3.0.1)