CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 101 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-3760 | Cri | 0.64 | 9.8 | 0.01 | Mar 7, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mia Technology Mia-Med. This issue affects Mia-Med: before 1.0.0.58. | ||
| CVE-2021-36392 | Cri | 0.64 | 9.8 | 0.01 | Mar 6, 2023 | In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses. | ||
| CVE-2023-0979 | Cri | 0.64 | 9.8 | 0.01 | Mar 6, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData MedDataPACS allows SQL Injection. This issue affects MedDataPACS : before 2023-03-03. | ||
| CVE-2023-24643 | Cri | 0.64 | 9.8 | 0.01 | Mar 3, 2023 | Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateBlankTxtview.php. | ||
| CVE-2023-24642 | Cri | 0.64 | 9.8 | 0.01 | Mar 3, 2023 | Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateTxtview.php. | ||
| CVE-2023-24641 | Cri | 0.64 | 9.8 | 0.01 | Mar 3, 2023 | Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateview.php. | ||
| CVE-2022-46501 | Cri | 0.64 | 9.8 | 0.01 | Mar 2, 2023 | Accruent LLC Maintenance Connection 2021 (all) & 2022.2 was discovered to contain a SQL injection vulnerability via the E-Mail to Work Order function. | ||
| CVE-2023-26780 | Cri | 0.64 | 9.8 | 0.01 | Mar 2, 2023 | CleverStupidDog yf-exam v 1.8.0 is vulnerable to SQL Injection. | ||
| CVE-2021-3854 | Cri | 0.64 | 9.8 | 0.01 | Mar 2, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Glox Technology Useroam Hotspot allows SQL Injection. This issue affects Useroam Hotspot: before 5.1.0.15. | ||
| CVE-2023-23315 | Cri | 0.64 | 9.8 | 0.01 | Mar 1, 2023 | The PrestaShop e-commerce platform module stripejs contains a Blind SQL injection vulnerability up to version 4.5.5. The method `stripejsValidationModuleFrontController::initContent()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a… | ||
| CVE-2023-1064 | Cri | 0.64 | 9.8 | 0.01 | Mar 1, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Uzay Baskul Weighbridge Automation Software allows SQL Injection. This issue affects Weighbridge Automation Software: before 1.1. | ||
| CVE-2023-24258 | Cri | 0.64 | 9.8 | 0.02 | Feb 27, 2023 | SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability via the _oups parameter. This vulnerability allows attackers to execute arbitrary code via a crafted POST request. | ||
| CVE-2023-24253 | Cri | 0.64 | 9.8 | 0.01 | Feb 27, 2023 | Domotica Labs srl Ikon Server before v2.8.6 was discovered to contain a SQL injection vulnerability. | ||
| CVE-2023-23155 | Cri | 0.64 | 9.8 | 0.01 | Feb 27, 2023 | Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the username parameter in the Admin Login. | ||
| CVE-2023-24206 | Cri | 0.64 | 9.8 | 0.01 | Feb 27, 2023 | Davinci v0.3.0-rc was discovered to contain a SQL injection vulnerability via the copyDisplay function. | ||
| CVE-2023-26550 | Cri | 0.64 | 9.8 | 0.01 | Feb 25, 2023 | A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attackers to execute arbitrary SQL commands via the memname JSON field. | ||
| CVE-2022-2504 | Cri | 0.64 | 9.8 | 0.01 | Feb 23, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SDD Computer Software SDD-Baro allows SQL Injection. This issue affects SDD-Baro: before 2.8.432. | ||
| CVE-2023-0939 | Cri | 0.64 | 9.8 | 0.01 | Feb 23, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NTN Information Technologies Online Services Software allows SQL Injection. This issue affects Online Services Software: before 1.17. | ||
| CVE-2022-48149 | Cri | 0.64 | 9.8 | 0.01 | Feb 22, 2023 | Online Student Admission System in PHP Free Source Code 1.0 was discovered to contain a SQL injection vulnerability via the username parameter. | ||
| CVE-2023-25157 | Cri | 0.64 | 9.8 | 0.85 | Feb 21, 2023 | GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. GeoServer includes support for the OGC Filter expression language and the OGC Common Query Language (CQL) as part of the Web Feature Service (WFS) and Web Map Service… |
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mia Technology Mia-Med. This issue affects Mia-Med: before 1.0.0.58.
- risk 0.64cvss 9.8epss 0.01
In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData MedDataPACS allows SQL Injection. This issue affects MedDataPACS : before 2023-03-03.
- risk 0.64cvss 9.8epss 0.01
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateBlankTxtview.php.
- risk 0.64cvss 9.8epss 0.01
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateTxtview.php.
- risk 0.64cvss 9.8epss 0.01
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateview.php.
- risk 0.64cvss 9.8epss 0.01
Accruent LLC Maintenance Connection 2021 (all) & 2022.2 was discovered to contain a SQL injection vulnerability via the E-Mail to Work Order function.
- risk 0.64cvss 9.8epss 0.01
CleverStupidDog yf-exam v 1.8.0 is vulnerable to SQL Injection.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Glox Technology Useroam Hotspot allows SQL Injection. This issue affects Useroam Hotspot: before 5.1.0.15.
- risk 0.64cvss 9.8epss 0.01
The PrestaShop e-commerce platform module stripejs contains a Blind SQL injection vulnerability up to version 4.5.5. The method `stripejsValidationModuleFrontController::initContent()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a…
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Uzay Baskul Weighbridge Automation Software allows SQL Injection. This issue affects Weighbridge Automation Software: before 1.1.
- risk 0.64cvss 9.8epss 0.02
SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability via the _oups parameter. This vulnerability allows attackers to execute arbitrary code via a crafted POST request.
- risk 0.64cvss 9.8epss 0.01
Domotica Labs srl Ikon Server before v2.8.6 was discovered to contain a SQL injection vulnerability.
- risk 0.64cvss 9.8epss 0.01
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the username parameter in the Admin Login.
- risk 0.64cvss 9.8epss 0.01
Davinci v0.3.0-rc was discovered to contain a SQL injection vulnerability via the copyDisplay function.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attackers to execute arbitrary SQL commands via the memname JSON field.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SDD Computer Software SDD-Baro allows SQL Injection. This issue affects SDD-Baro: before 2.8.432.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NTN Information Technologies Online Services Software allows SQL Injection. This issue affects Online Services Software: before 1.17.
- risk 0.64cvss 9.8epss 0.01
Online Student Admission System in PHP Free Source Code 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.
- risk 0.64cvss 9.8epss 0.85
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. GeoServer includes support for the OGC Filter expression language and the OGC Common Query Language (CQL) as part of the Web Feature Service (WFS) and Web Map Service…