Description
Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application.
Remediation
References
Related Vulnerabilities
Grafana Missing Authentication for Critical Function Vulnerability (CVE-2022-28660)
WordPress Plugin Debug Log Manager Information Disclosure (2.2.2)
Jenkins Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-3665)
WordPress Incorrect Default Permissions Vulnerability (CVE-2011-1762)