CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,812)
page 10 of 1,041| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-23163 | Cri | 0.67 | 9.8 | 0.04 | Feb 10, 2023 | Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter. | ||
| CVE-2023-23162 | Cri | 0.67 | 9.8 | 0.04 | Feb 10, 2023 | Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at product.php. | ||
| CVE-2022-45297 | Cri | 0.67 | 9.8 | 0.03 | Jan 31, 2023 | EQ v1.5.31 to v2.2.0 was discovered to contain a SQL injection vulnerability via the UserPwd parameter. | ||
| CVE-2023-23488 | Cri | 0.67 | 9.8 | 0.92 | Jan 20, 2023 | The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST route. | ||
| CVE-2022-2840 | Cri | 0.67 | 9.8 | 0.13 | Sep 19, 2022 | The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injections | ||
| CVE-2022-2754 | Cri | 0.67 | 9.8 | 0.38 | Sep 19, 2022 | The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters before using them in SQL statements, which could allow unauthenticated attackers to perform SQL Injection attacks | ||
| CVE-2022-31056 | Cri | 0.67 | 9.8 | 0.09 | Jun 28, 2022 | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions all assistance forms (Ticket/Change/Problem) permit sql injection on the actor fields. This issue has been resolved… | ||
| CVE-2022-1905 | Cri | 0.67 | 9.8 | 0.37 | Jun 20, 2022 | The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection | ||
| CVE-2022-27412 | Cri | 0.67 | 9.8 | 0.04 | May 9, 2022 | Explore CMS v1.0 was discovered to contain a SQL injection vulnerability via a /page.php?id= request. | ||
| CVE-2022-0773 | Cri | 0.67 | 9.8 | 0.43 | May 2, 2022 | The Documentor WordPress plugin through 1.5.3 fails to sanitize and escape user input before it is being interpolated in an SQL statement and then executed, leading to an SQL Injection exploitable by unauthenticated users. | ||
| CVE-2021-43481 | Cri | 0.67 | 9.8 | 0.06 | Apr 20, 2022 | An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php. | ||
| CVE-2021-43650 | Cri | 0.67 | 9.8 | 0.06 | Mar 22, 2022 | WebRun 3.6.0.42 is vulnerable to SQL Injection via the P_0 parameter used to set the username during the login process. | ||
| CVE-2022-24263 | Cri | 0.67 | 9.8 | 0.08 | Jan 31, 2022 | Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter. | ||
| CVE-2022-23366 | Cri | 0.67 | 9.8 | 0.07 | Jan 21, 2022 | HMS v1.0 was discovered to contain a SQL injection vulnerability via patientlogin.php. | ||
| CVE-2021-45814 | Cri | 0.67 | 9.8 | 0.06 | Dec 28, 2021 | Nettmp NNT 5.1 is affected by a SQL injection vulnerability. An attacker can bypass authentication and access the panel with an administrative account. | ||
| CVE-2021-44655 | Cri | 0.67 | 9.8 | 0.06 | Dec 15, 2021 | Online Pre-owned/Used Car Showroom Management System 1.0 contains a SQL injection authentication bypass vulnerability. Admin panel authentication can be bypassed due to SQL injection vulnerability in the login form allowing attacker to get admin access on the application. | ||
| CVE-2021-44653 | Cri | 0.67 | 9.8 | 0.06 | Dec 15, 2021 | Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability. The Admin panel authentication can be bypassed due to SQL injection vulnerability in the login form allowing attacker to gain access as admin to the application. | ||
| CVE-2021-42580 | Cri | 0.67 | 9.8 | 0.10 | Nov 15, 2021 | Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and authenticated file upload in (Master.php) file , we can craft these two vunlerablities to get unauthenticated remote command execution. | ||
| CVE-2021-43140 | Cri | 0.67 | 9.8 | 0.05 | Nov 3, 2021 | SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login. | ||
| CVE-2021-40617 | Cri | 0.67 | 9.8 | 0.05 | Oct 11, 2021 | An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php. |
- risk 0.67cvss 9.8epss 0.04
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter.
- risk 0.67cvss 9.8epss 0.04
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at product.php.
- risk 0.67cvss 9.8epss 0.03
EQ v1.5.31 to v2.2.0 was discovered to contain a SQL injection vulnerability via the UserPwd parameter.
- risk 0.67cvss 9.8epss 0.92
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST route.
- risk 0.67cvss 9.8epss 0.13
The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using them in SQL statements via various AJAX actions available to both unauthenticated and authenticated users, leading to SQL injections
- risk 0.67cvss 9.8epss 0.38
The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters before using them in SQL statements, which could allow unauthenticated attackers to perform SQL Injection attacks
- risk 0.67cvss 9.8epss 0.09
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions all assistance forms (Ticket/Change/Problem) permit sql injection on the actor fields. This issue has been resolved…
- risk 0.67cvss 9.8epss 0.37
The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
- risk 0.67cvss 9.8epss 0.04
Explore CMS v1.0 was discovered to contain a SQL injection vulnerability via a /page.php?id= request.
- risk 0.67cvss 9.8epss 0.43
The Documentor WordPress plugin through 1.5.3 fails to sanitize and escape user input before it is being interpolated in an SQL statement and then executed, leading to an SQL Injection exploitable by unauthenticated users.
- risk 0.67cvss 9.8epss 0.06
An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php.
- risk 0.67cvss 9.8epss 0.06
WebRun 3.6.0.42 is vulnerable to SQL Injection via the P_0 parameter used to set the username during the login process.
- risk 0.67cvss 9.8epss 0.08
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter.
- risk 0.67cvss 9.8epss 0.07
HMS v1.0 was discovered to contain a SQL injection vulnerability via patientlogin.php.
- risk 0.67cvss 9.8epss 0.06
Nettmp NNT 5.1 is affected by a SQL injection vulnerability. An attacker can bypass authentication and access the panel with an administrative account.
- risk 0.67cvss 9.8epss 0.06
Online Pre-owned/Used Car Showroom Management System 1.0 contains a SQL injection authentication bypass vulnerability. Admin panel authentication can be bypassed due to SQL injection vulnerability in the login form allowing attacker to get admin access on the application.
- risk 0.67cvss 9.8epss 0.06
Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability. The Admin panel authentication can be bypassed due to SQL injection vulnerability in the login form allowing attacker to gain access as admin to the application.
- risk 0.67cvss 9.8epss 0.10
Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and authenticated file upload in (Master.php) file , we can craft these two vunlerablities to get unauthenticated remote command execution.
- risk 0.67cvss 9.8epss 0.05
SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login.
- risk 0.67cvss 9.8epss 0.05
An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php.