CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 102 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-45677 | Cri | 0.64 | 9.8 | 0.01 | Feb 21, 2023 | SQL Injection Vulnerability in tanujpatra228 Tution Management System (TMS) via the email parameter to processes/student_login.process.php. | ||
| CVE-2022-45564 | Cri | 0.64 | 9.8 | 0.01 | Feb 21, 2023 | SQL Injection vulnerability in znfit Home improvement ERP management system V50_20220207,v42 allows attackers to execute arbitrary sql commands via the userCode parameter to the wechat applet. | ||
| CVE-2023-23279 | Cri | 0.64 | 9.8 | 0.01 | Feb 17, 2023 | Canteen Management System 1.0 is vulnerable to SQL Injection via /php_action/getOrderReport.php. | ||
| CVE-2021-33948 | Cri | 0.64 | 9.8 | 0.01 | Feb 17, 2023 | SQL injection vulnerability in FantasticLBP Hotels Server v1.0 allows attacker to execute arbitrary code via the username parameter. | ||
| CVE-2020-29168 | Cri | 0.64 | 9.8 | 0.01 | Feb 17, 2023 | SQL Injection vulnerability in Projectworlds Online Doctor Appointment Booking System, allows attackers to gain sensitive information via the q parameter to the getuser.php endpoint. | ||
| CVE-2023-24221 | Cri | 0.64 | 9.8 | 0.01 | Feb 17, 2023 | LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/DeptMapper.xml. | ||
| CVE-2023-24220 | Cri | 0.64 | 9.8 | 0.01 | Feb 17, 2023 | LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/RoleMapper.xml. | ||
| CVE-2023-24219 | Cri | 0.64 | 9.8 | 0.01 | Feb 17, 2023 | LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/UserMapper.xml. | ||
| CVE-2021-33925 | Cri | 0.64 | 9.8 | 0.01 | Feb 15, 2023 | SQL Injection vulnerability in nitinparashar30 cms-corephp through commit bdabe52ef282846823bda102728a35506d0ec8f9 (May 19, 2021) allows unauthenticated attackers to gain escilated privledges via a crafted login. | ||
| CVE-2020-21120 | Cri | 0.64 | 9.8 | 0.01 | Feb 15, 2023 | SQL Injection vulnerability in file home\controls\cart.class.php in UQCMS 2.1.3, allows attackers execute arbitrary commands via the cookie_cart parameter to /index.php/cart/num. | ||
| CVE-2020-21119 | Cri | 0.64 | 9.8 | 0.01 | Feb 15, 2023 | SQL Injection vulnerability in Kliqqi-CMS 2.0.2 in admin/admin_update_module_widgets.php in recordIDValue parameter, allows attackers to gain escalated privileges and execute arbitrary code. | ||
| CVE-2023-24084 | Cri | 0.64 | 9.8 | 0.01 | Feb 13, 2023 | ChiKoi v1.0 was discovered to contain a SQL injection vulnerability via the load_file function. | ||
| CVE-2022-4445 | Cri | 0.64 | 9.8 | 0.01 | Feb 13, 2023 | The FL3R FeelBox WordPress plugin through 8.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. | ||
| CVE-2022-4557 | Cri | 0.64 | 9.8 | 0.01 | Feb 12, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection. This issue affects Smartpower Web: before 23.01.01. | ||
| CVE-2022-45526 | Cri | 0.64 | 9.8 | 0.01 | Feb 8, 2023 | SQL Injection vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows attackers to execute arbitrary commands via the ad parameter to /admin_area/login_transfer.php. | ||
| CVE-2023-24201 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2023 | Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at get_ticket.php. | ||
| CVE-2023-24200 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2023 | Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at save_ticket.php. | ||
| CVE-2023-24199 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2023 | Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at delete_ticket.php. | ||
| CVE-2023-24198 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2023 | Raffle Draw System v1.0 was discovered to contain multiple SQL injection vulnerabilities at save_winner.php via the ticket_id and draw parameters. | ||
| CVE-2021-37497 | Cri | 0.64 | 9.8 | 0.01 | Feb 3, 2023 | SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted GET request. |
- risk 0.64cvss 9.8epss 0.01
SQL Injection Vulnerability in tanujpatra228 Tution Management System (TMS) via the email parameter to processes/student_login.process.php.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in znfit Home improvement ERP management system V50_20220207,v42 allows attackers to execute arbitrary sql commands via the userCode parameter to the wechat applet.
- risk 0.64cvss 9.8epss 0.01
Canteen Management System 1.0 is vulnerable to SQL Injection via /php_action/getOrderReport.php.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in FantasticLBP Hotels Server v1.0 allows attacker to execute arbitrary code via the username parameter.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in Projectworlds Online Doctor Appointment Booking System, allows attackers to gain sensitive information via the q parameter to the getuser.php endpoint.
- risk 0.64cvss 9.8epss 0.01
LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/DeptMapper.xml.
- risk 0.64cvss 9.8epss 0.01
LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/RoleMapper.xml.
- risk 0.64cvss 9.8epss 0.01
LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/UserMapper.xml.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in nitinparashar30 cms-corephp through commit bdabe52ef282846823bda102728a35506d0ec8f9 (May 19, 2021) allows unauthenticated attackers to gain escilated privledges via a crafted login.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in file home\controls\cart.class.php in UQCMS 2.1.3, allows attackers execute arbitrary commands via the cookie_cart parameter to /index.php/cart/num.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in Kliqqi-CMS 2.0.2 in admin/admin_update_module_widgets.php in recordIDValue parameter, allows attackers to gain escalated privileges and execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
ChiKoi v1.0 was discovered to contain a SQL injection vulnerability via the load_file function.
- risk 0.64cvss 9.8epss 0.01
The FL3R FeelBox WordPress plugin through 8.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection. This issue affects Smartpower Web: before 23.01.01.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows attackers to execute arbitrary commands via the ad parameter to /admin_area/login_transfer.php.
- risk 0.64cvss 9.8epss 0.01
Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at get_ticket.php.
- risk 0.64cvss 9.8epss 0.01
Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at save_ticket.php.
- risk 0.64cvss 9.8epss 0.01
Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at delete_ticket.php.
- risk 0.64cvss 9.8epss 0.01
Raffle Draw System v1.0 was discovered to contain multiple SQL injection vulnerabilities at save_winner.php via the ticket_id and draw parameters.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted GET request.