Vulnerability record · CVE-2020-7471 · published 3 February 2020
CVE-2020-7471: Django StringAgg delimiter SQL injection
Djangoproject · Django
Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allow SQL injection when untrusted data is used as the delimiter of a contrib.postgres.aggregates.StringAgg instance. A crafted delimiter breaks escaping and injects malicious SQL, which matters because such delimiters are commonly taken from user input in data-export features.
Description
Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in Django applications that offer downloads of data as a series of rows with a user-specified column delimiter). By passing a suitably crafted delimiter to a contrib.postgres.aggregates.StringAgg instance, it was possible to break escaping and inject malicious SQL.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 9.8 and a 99.2nd percentile EPSS score indicate severe, likely-exploitable SQL injection, though there is no KEV listing or documented in-the-wild use.
What it is
Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allow SQL injection when untrusted data is used as the delimiter of a contrib.postgres.aggregates.StringAgg instance. A crafted delimiter breaks escaping and injects malicious SQL, which matters because such delimiters are commonly taken from user input in data-export features.
Impact
An attacker can inject arbitrary SQL into queries built with StringAgg, potentially reading or modifying database contents and, depending on database privileges, executing database-side operations.
Attack surface
Reached over the network through any Django application that passes user-controlled data as a StringAgg delimiter, such as a download endpoint with a user-specified column delimiter. The CVSS vector indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware group use is documented, but EPSS is 0.65575 (99.2nd percentile), indicating a high modeled likelihood of exploitation. References include a vendor patch commit and multiple vendor advisories.
What to do
- Upgrade Django to 1.11.28, 2.2.10, 3.0.3 or later; the patch commit is eb31d845323618d688ad429479c6dda973056136.
- Apply distribution updates (Debian DSA-4629, Ubuntu USN-4264-1, Gentoo GLSA 202004-17, Fedora) where Django is packaged.
- Never pass untrusted input directly as a StringAgg delimiter; validate or whitelist allowed delimiter values.
- Audit application code for StringAgg usage with user-supplied delimiters and replace with parameterized or fixed delimiters.
- Restrict database account privileges for the Django application to limit the impact of successful injection.
Detection
- Search application code and logs for StringAgg usage where the delimiter originates from request parameters.
- Monitor database query logs for anomalous SQL in aggregate or string_agg statements.
- Alert on requests to data-export or download endpoints that carry unusual delimiter parameter values.
- Review database error logs for syntax errors or unexpected query patterns tied to export functionality.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-7471 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-7471), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.