PyMySQL is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
70
High Risk
Affected versions allow SQL injection through Cursor.callproc() when untrusted input is used as the procedure name. An attacker can supply a crafted procedure identifier to manipulate the generated SQL query and execute unintended database commands.
You are affected if you are using a version that falls within the vulnerable range.
PyMySQL is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.1 - 1.1.2.
Upgrade the PyMySQL library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant