CVE-2024-9774

CVSS 3.0 Score 6.5 of 10 (medium)

Details

Published Dec 27, 2024
Updated: Feb 7, 2025
CWE ID 150

Summary

CVE-2024-9774 is a newly disclosed vulnerability affecting the python-sql library. This issue arises due to the library's failure to properly escape non-Expression characters when using unary operators. An attacker can potentially exploit this vulnerability by injecting malicious SQL statements, leading to unauthorized data access or modification. Developers should upgrade their python-sql packages to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share