{"id":"CVE-2021-30459","details":"A SQL Injection issue in the SQL Panel in Jazzband Django Debug Toolbar before 1.11.1, 2.x before 2.2.1, and 3.x before 3.2.1 allows attackers to execute SQL statements by changing the raw_sql input field of the SQL explain, analyze, or select form.","aliases":["GHSA-pghf-347x-c2gj","PYSEC-2021-10"],"modified":"2026-08-27T08:15:15.096224Z","published":"2021-04-14T18:15:14.877Z","related":["openSUSE-SU-2024:11225-1","openSUSE-SU-2024:14137-1","openSUSE-SU-2026:11271-1"],"references":[{"type":"ADVISORY","url":"https://github.com/jazzband/django-debug-toolbar/releases"},{"type":"ADVISORY","url":"https://www.djangoproject.com/weblog/2021/apr/14/debug-toolbar-security-releases/"},{"type":"FIX","url":"https://github.com/jazzband/django-debug-toolbar/security/advisories/GHSA-pghf-347x-c2gj"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/django-commons/django-debug-toolbar","events":[{"introduced":"dab9a28e6d80aa65f595c0bb48846aa6018f0473"},{"fixed":"bc08f692742981b4155818639d6f40df76d1cee5"},{"introduced":"0"},{"fixed":"5e6750bf89e834fa961b4abdbfe361f7ea1b04ab"},{"fixed":"f14fca80fb203f140edb89d5a33ff027aa38ea34"}],"database_specific":{"extracted_events":[{"introduced":"0.10.0"},{"fixed":"1.11.1"},{"introduced":"2.0.0"},{"fixed":"2.2.1"},{"introduced":"3.0.0"},{"fixed":"3.2.1"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:jazzband:django_debug_toolbar:*:*:*:*:*:*:*:*"}}],"versions":["1.11","2.2","3.1.1","3.1","3.0","3.0a4","3.0a3","3.0a2","3.0a1","2.1","2.0","2.0a1","1.10.1","1.10","1.9.1","1.9","1.8","1.7","1.6","1.5","1.4","1.3.2","1.3","1.2.2","1.2.1","1.2","1.1","1.0.1","1.0","0.10.2","0.10.1","0.10.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-30459.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}