PT-2024-2256 · Microsoft · Django Backend For Sql Server

·

CVE-2024-26164

·

Published

2024-03-12

·

Updated

2026-07-07

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Django Backend for SQL Server (affected versions not specified)
Description The issue is related to the failure to protect the SQL query structure when handling an unsanitized parameter, which can be exploited by a remote attacker to execute arbitrary code using a specially crafted query.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-02189
CVE-2024-26164
GHSA-VMQV-47J8-GWV8
PYSEC-2026-1684

Affected Products

Django Backend For Sql Server