CVE-2024-26164HighCVSS 8.8
Microsoft Django Backend for SQL Server Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
How could an attacker exploit the vulnerability? An attacker could use the unsanitized parameter into a SQL query to trigger SQL Injection.
According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? Successful exploitation of this vulnerability simply requires the attacker or targeted user to leverage a Microsoft Access application to automatically talk to a SQL Server while utilizing a remote SQL Server address that they control.
🎯 Affected products1
- SQL Server backend for Django
✅ Remediation
KBRelease Notes (Security Update) — fixed build 1.4.1