CVE-2022-28347 | Django up to 2.2.27/3.2.12/4.0.3 Dictionary QuerySet.explain options sql injection (EUVD-2022-0088)
A vulnerability has been found in Django up to 2.2.27/3.2.12/4.0.3 and classified as critical. This affects the function QuerySet.explain of the component Dictionary Handler. The manipulation of the argument options leads to sql injection.
This vulnerability is listed as CVE-2022-28347. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.