Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-57833 PoC — Django SQL注入漏洞

Source
Associated Vulnerability
Title: Django SQL注入漏洞 (CVE-2025-57833)
Description:An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed QuerySet.annotate() or QuerySet.alias().
Description
We've set up an environment to test CVE-2025-57833. This environment was built using AI, so it's subject to ongoing modification.
Readme
# Django SQL Injection Test Environment (CVE-2025-57833)

This is a Docker-based test environment for demonstrating the critical SQL injection vulnerability CVE-2025-57833 in Django.

## Key Points

*   **Vulnerability**: CVE-2025-57833 is a critical SQL injection vulnerability in the Django ORM that occurs when using `FilteredRelation` with `select_related`.
*   **Root Cause**: The vulnerability is caused by using unsanitized user input directly as a field name in a `FilteredRelation`, which allows for the manipulation of the generated SQL query.
*   **Impact**: This can lead to information disclosure and Remote Code Execution (RCE) on the PostgreSQL database server, with a CVSS score of 9.8 (Critical).
*   **Attack Vector**: Attackers can exploit this by sending a malicious payload in the `search_field` of a POST request to the `/api/vulnerable-search/` endpoint.
*   **Mitigation**: The recommended fix is to use a whitelist to validate user input before it is passed to the Django ORM.

## References

- **Medium Article**: [Django Unauthenticated 0-click RCE and SQL Injection using Default Configuration](https://medium.com/@EyalSec/django-unauthenticated-0-click-rce-and-sql-injection-using-default-configuration-059964f3f898) by Eyal Gabay (@EyalSec)
- **Django Security Release**: [Django security releases issued: 5.2.6, 5.1.12, and 4.2.24](https://www.djangoproject.com/weblog/2025/sep/03/security-releases/)
- **NullSecurityx Article**: [CVE-2025-57833 Django SQL Injection](https://nullsecurityx.codes/cve-2025-57833-django-sql-injection)

For more detailed documentation, please see [document/README.md](document/README.md).
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →