Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-7471

67
FAUCET Score

CVE-2020-7471 is a critical SQL Injection vulnerability affecting Django versions 1.11, 2.2, and 3.0. It allows an attacker to inject malicious SQL queries by providing untrusted data as a StringAgg delimiter, particularly in applications offering data downloads with user-specified delimiters. This vulnerability has a CVSS score of 9.8 (Critical), indicating a high potential for complete compromise of confidentiality, integrity, and availability, with no user interaction or authentication required. Despite its severity, there is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.11, < 1.11.28CPE matchmatch criteria
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
>= 2.2, < 2.2.10CPE matchmatch criteria
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
>= 3.0, < 3.0.3CPE matchmatch criteria
cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
65.34%
Probability of exploitation in next 30 days
EPSS Percentile
99.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.6534 is in the 97th percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: djangoFixed in: 1.11.28
pippatch availablevia ghsa
Product: DjangoFixed in: 2.2.10
pippatch availablevia ghsa
Product: DjangoFixed in: 3.0.3
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenStack Platform 13 (Queens)Fixed in: python-django
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenStack Platform 15 (Stein)Fixed in: python-django
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenStack Platform 16 (Train)Fixed in: python-django
redhatvendor investigatingvia redhat_api
Product: Red Hat Satellite 6Fixed in: python-django
redhatvendor investigatingvia redhat_api
Product: Red Hat Storage 3Fixed in: python-django
redhatend of lifevia redhat_api
Product: Red Hat Update Infrastructure 3 for Cloud ProvidersFixed in: python-django

Vendor Advisories (2)

pipGHSA-hmr4-m2h5-33qxcritical

SQL injection in Django

Feb 11, 2020
redhatCVE-2020-7471Important

django: potential SQL injection via StringAgg(delimiter)

Feb 3, 2020

References

docs.djangoproject.com / en/3.0/releases/security
Vendor Advisory
github.com / django/django/commit/eb31d845323618d688ad429479c6dda973056136
PatchThird Party Advisory
groups.google.com / forum
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/4A2AP4T7RKPBCLTI2NNQG3T6MINDUUMZ
seclists.org / bugtraq/2020/Feb/30
security.gentoo.org / glsa/202004-17
security.netapp.com / advisory/ntap-20200221-0006
usn.ubuntu.com / 4264-1
debian.org / security/2020/dsa-4629
djangoproject.com / weblog/2020/feb/03/security-releases
Vendor Advisory
openwall.com / lists/oss-security/2020/02/03/1
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2020/02/03/1
Mailing ListThird Party Advisory