VYPR

CWE-707

Improper Neutralization

PillarIncomplete

Description

The product does not ensure or incorrectly ensures that structured messages or data are well-formed and that certain security properties are met before being read from an upstream component or sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-250 · CAPEC-276 · CAPEC-277 · CAPEC-278 · CAPEC-279 · CAPEC-3 · CAPEC-43 · CAPEC-468 · CAPEC-52 · CAPEC-53 · CAPEC-64 · CAPEC-7 · CAPEC-78 · CAPEC-79 · CAPEC-83 · CAPEC-84

CVEs mapped to this weakness (253)

page 6 of 13
  • CVE-2022-3827MedNov 2, 2022
    risk 0.34cvss 6.3epss 0.01

    A vulnerability was found in centreon. It has been declared as critical. This vulnerability affects unknown code of the file formContactGroup.php of the component Contact Groups Form. The manipulation of the argument cg_id leads to sql injection. The attack can be initiated…

  • CVE-2022-3802MedNov 1, 2022
    risk 0.34cvss 6.3epss 0.01

    A vulnerability has been found in IBAX go-ibax and classified as critical. This vulnerability affects unknown code of the file /api/v2/open/rowsInfo. The manipulation of the argument where leads to sql injection. The attack can be initiated remotely. The exploit has been…

  • CVE-2022-3800MedNov 1, 2022
    risk 0.34cvss 6.3epss 0.02

    A vulnerability, which was classified as critical, has been found in IBAX go-ibax. Affected by this issue is some unknown functionality of the file /api/v2/open/rowsInfo. The manipulation of the argument table_name leads to sql injection. The attack may be launched remotely. The…

  • CVE-2022-3799MedNov 1, 2022
    risk 0.34cvss 6.3epss 0.01

    A vulnerability classified as critical was found in IBAX go-ibax. Affected by this vulnerability is an unknown functionality of the file /api/v2/open/tablesInfo. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the…

  • CVE-2022-3798MedNov 1, 2022
    risk 0.34cvss 6.3epss 0.01

    A vulnerability classified as critical has been found in IBAX go-ibax. Affected is an unknown function of the file /api/v2/open/tablesInfo. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may…

  • CVE-2022-23004MedJul 29, 2022
    risk 0.34cvss 5.3epss 0.01

    When computing a shared secret or point multiplication on the NIST P-256 curve using a public key with an X coordinate of zero, an error is returned from the library, and an invalid unreduced value is written to the output buffer. This may be leveraged by an attacker to cause an…

  • CVE-2022-4248MedDec 1, 2022
    risk 0.33cvss 5.0epss 0.00

    A vulnerability, which was classified as critical, has been found in Movie Ticket Booking System. This issue affects some unknown processing of the file editBooking.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit…

  • CVE-2022-4222MedNov 30, 2022
    risk 0.33cvss 5.0epss 0.01

    A vulnerability was found in SourceCodester Canteen Management System. It has been rated as critical. This issue affects the function query of the file ajax_invoice.php of the component POST Request Handler. The manipulation of the argument search leads to sql injection. The…

  • CVE-2022-3733MedOct 28, 2022
    risk 0.33cvss 5.0epss 0.01

    A vulnerability was found in SourceCodester Web-Based Student Clearance System. It has been classified as critical. This affects an unknown part of the file Admin/edit-admin.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack…

  • CVE-2022-3714MedOct 27, 2022
    risk 0.33cvss 5.0epss 0.00

    A vulnerability classified as critical has been found in SourceCodester Online Medicine Ordering System 1.0. Affected is an unknown function of the file admin/?page=orders/view_order. The manipulation of the argument id leads to sql injection. It is possible to launch the attack…

  • CVE-2022-3414MedOct 7, 2022
    risk 0.33cvss 5.0epss 0.01

    A vulnerability was found in SourceCodester Web-Based Student Clearance System. It has been classified as critical. Affected is an unknown function of the file /Admin/login.php of the component POST Parameter Handler. The manipulation of the argument txtusername leads to sql…

  • CVE-2025-1611MedFeb 24, 2025
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in ShopXO up to 6.4.0. It has been classified as problematic. This affects an unknown part of the file app/service/ThemeAdminService.php of the component Template Handler. The manipulation leads to injection. It is possible to initiate the attack…

  • CVE-2022-4282MedDec 5, 2022
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SpringBootCMS and classified as critical. Affected by this issue is some unknown functionality of the component Template Management. The manipulation leads to injection. The attack may be launched remotely. The exploit has been disclosed to the…

  • CVE-2022-4278MedDec 3, 2022
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Human Resource Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /hrm/employeeadd.php. The manipulation of the argument empid leads to sql injection. The attack may be…

  • CVE-2022-4052MedNov 17, 2022
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in Student Attendance Management System and classified as critical. This issue affects some unknown processing of the file /Admin/createClass.php. The manipulation of the argument Id leads to sql injection. The attack may be initiated remotely. The…

  • CVE-2022-4015MedNov 16, 2022
    risk 0.31cvss 4.7epss 0.00

    A vulnerability, which was classified as critical, was found in Sports Club Management System 119. This affects an unknown part of the file admin/make_payments.php. The manipulation of the argument m_id/plan leads to sql injection. It is possible to initiate the attack remotely.…

  • CVE-2022-3868MedNov 5, 2022
    risk 0.31cvss 4.7epss 0.00

    A vulnerability classified as critical has been found in SourceCodester Sanitization Management System. Affected is an unknown function of the file /php-sms/classes/Master.php?f=save_quote. The manipulation of the argument id leads to sql injection. It is possible to launch the…

  • CVE-2026-10222MedJun 1, 2026
    risk 0.29cvss 5.6epss 0.00

    A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.30. Affected by this issue is the function _sanitize_env_lines of the file hermes_cli/config.py. The manipulation results in injection. It is possible to launch the attack remotely. The attack requires…

  • CVE-2020-36626MedDec 27, 2022
    risk 0.29cvss 5.5epss 0.01

    A vulnerability classified as critical has been found in Modern Tribe Panel Builder Plugin. Affected is the function add_post_content_filtered_to_search_sql of the file ModularContent/SearchFilter.php. The manipulation leads to sql injection. It is possible to launch the attack…

  • CVE-2021-4262MedDec 19, 2022
    risk 0.29cvss 5.5epss 0.01

    A vulnerability classified as critical was found in laravel-jqgrid. Affected by this vulnerability is the function getRows of the file src/Mgallegos/LaravelJqgrid/Repositories/EloquentRepositoryAbstract.php. The manipulation leads to sql injection. The name of the patch is…