CVE-2024-26164HighCVSS 8.8

Microsoft Django Backend for SQL Server Remote Code Execution Vulnerability

Published
March 12, 2024
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

How could an attacker exploit the vulnerability? An attacker could use the unsanitized parameter into a SQL query to trigger SQL Injection.

According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? Successful exploitation of this vulnerability simply requires the attacker or targeted user to leverage a Microsoft Access application to automatically talk to a SQL Server while utilizing a remote SQL Server address that they control.

🎯 Affected products1

  • SQL Server backend for Django

✅ Remediation

KBRelease Notes (Security Update) — fixed build 1.4.1

🔗 References (3)