Description
Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a suitably crafted tolerance to GIS functions and aggregates on Oracle, it was possible to break escaping and inject malicious SQL.
Remediation
References
Related Vulnerabilities
WordPress Plugin Easy Author Image Information Disclosure (1.5)
SharePoint Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-1261)
WordPress Cryptographic Issues Vulnerability (CVE-2009-3622)
Oracle JRE CVE-2013-5782 Vulnerability (CVE-2013-5782)
WordPress Plugin SearchWP Live Ajax Search Directory Traversal (1.6.2)