![]() |
|
HackerOne Disclosed Reports - 2025-09-12 - Printable Version +- Dark C0d3rs (https://darkcoders.wiki) +-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log) +--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports) +--- Thread: HackerOne Disclosed Reports - 2025-09-12 (/Thread-HackerOne-Disclosed-Reports-2025-09-12) |
HackerOne disclosed reports - 2025-09-12 - hashXploiter - 09-13-2025
High
resolved SQL injection in JSONField KeyTransformBug reported by Eyal Gabay was disclosed at September 12, 2025, 12:28 am | SQL Injection A vulnerability was discovered in the JSONField KeyTransform functionality of Django. The vulnerability allowed SQL injection attacks by crafting malicious user input for the .values() method. The vulnerability was demonstrated in the Django test suite, where a SQL syntax error was triggered by inputting a specifically crafted string. |