CRITICAL 9.8 PyPI

Code Injection in Django

GHSA-rvq6-mrpv-m6rm · CVE-2014-0472 · PYSEC-2014-1

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows remote attackers to import and execute arbitrary Python modules by leveraging a view that constructs URLs using user input and a "dotted Python path."

Ready to move

Start Securing

Free, no credit card | First findings in minutes