1
0
mirror of https://github.com/django/django.git synced 2025-10-09 06:49:12 +00:00
Mariusz Felisiak 01d2d770e2 [5.1.x] Fixed CVE-2025-59681 -- Protected QuerySet.annotate(), alias(), aggregate(), and extra() against SQL injection in column aliases on MySQL/MariaDB.
Thanks sw0rd1ight for the report.

Follow up to 93cae5cb2f9a4ef1514cf1a41f714fef08005200.

Backport of 41b43c74bda19753c757036673ea9db74acf494a from main.
2025-10-01 08:53:17 -04:00
..
2024-01-26 12:45:07 +01:00