QuerySet.extra() splices raw SQL fragments into select, where, tables, and order_by—when those fragments carry user input the result is SQL injection.
Expanding attacker-controlled dictionaries into QuerySet.filter()/exclude() and trusting user-supplied field lookups exposes unintended columns and boolean logic.
How string-formatted queries in Django's raw(), extra(), and the low-level cursor API become SQL injection despite the ORM, with concrete payloads.
We use cookies to enhance your experience. Learn more