Related Vulnerabilities: CVE-2020-7471  

django.contrib.postgres.aggregates.StringAgg aggregation function was subject to SQL injection, using a suitably crafted delimiter.

Severity Medium

Remote Yes

Type Sql injection

Description

django.contrib.postgres.aggregates.StringAgg aggregation function was subject to SQL injection, using a suitably crafted delimiter.

AVG-1091 python-django 3.0.2-1 3.0.3-1 Medium Fixed

https://www.djangoproject.com/weblog/2020/feb/03/security-releases/