HIGH 7.5 PyPI

Django database denial-of-service with ModelMultipleChoiceField

GHSA-6g95-x6cj-mg4v · CVE-2015-0222 · PYSEC-2015-7

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries.

Ready to move

Start Securing

Free, no credit card | First findings in minutes