CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 122 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-30413 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/classes/Master.php?f=delete_application. | ||
| CVE-2022-30407 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Pharmacy Sales And Inventory System v1.0 is vulnerable to SQL Injection via /pharmacy-sales-and-inventory-system/manage_user.php?id=. | ||
| CVE-2022-30395 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_cart. | ||
| CVE-2022-30392 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_sub_category. | ||
| CVE-2022-30391 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_category. | ||
| CVE-2022-30387 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=pay_order. | ||
| CVE-2022-30386 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_featured. | ||
| CVE-2022-30385 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_order. | ||
| CVE-2022-30384 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_inventory. | ||
| CVE-2022-30370 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/classes/Master.php?f=delete_cargo_type. | ||
| CVE-2022-30001 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editAgent.php?agent_id=. | ||
| CVE-2022-30000 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editPayment.php?recipt_no=. | ||
| CVE-2022-29999 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editClient.php?client_id=. | ||
| CVE-2022-29998 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/clientStatus.php?client_id=. | ||
| CVE-2022-29746 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Money Transfer Management System 1.0 is vulnerable to SQL Injection via /mtms/classes/Users.php?f=delete. | ||
| CVE-2022-29745 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Money Transfer Management System 1.0 is vulnerable to SQL Injection via \mtms\classes\Master.php?f=delete_transaction. | ||
| CVE-2022-29741 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Money Transfer Management System 1.0 is vulnerable to SQL Injection via \mtms\classes\Master.php?f=delete_fee. | ||
| CVE-2022-29739 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Money Transfer Management System 1.0 is vulnerable to SQL Injection via /mtms/admin/?page=user/manage_user&id=. | ||
| CVE-2022-29738 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | Money Transfer Management System 1.0 is vulnerable to SQL Injection via /mtms/admin/?page=transaction/send&id=, id. | ||
| CVE-2022-29306 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2022 | IonizeCMS v1.0.8.1 was discovered to contain a SQL injection vulnerability via the id_page parameter in application/models/article_model.php. |
- risk 0.64cvss 9.8epss 0.01
Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/classes/Master.php?f=delete_application.
- risk 0.64cvss 9.8epss 0.01
Pharmacy Sales And Inventory System v1.0 is vulnerable to SQL Injection via /pharmacy-sales-and-inventory-system/manage_user.php?id=.
- risk 0.64cvss 9.8epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_cart.
- risk 0.64cvss 9.8epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_sub_category.
- risk 0.64cvss 9.8epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_category.
- risk 0.64cvss 9.8epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=pay_order.
- risk 0.64cvss 9.8epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_featured.
- risk 0.64cvss 9.8epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_order.
- risk 0.64cvss 9.8epss 0.01
Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_inventory.
- risk 0.64cvss 9.8epss 0.01
Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/classes/Master.php?f=delete_cargo_type.
- risk 0.64cvss 9.8epss 0.01
Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editAgent.php?agent_id=.
- risk 0.64cvss 9.8epss 0.01
Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editPayment.php?recipt_no=.
- risk 0.64cvss 9.8epss 0.01
Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editClient.php?client_id=.
- risk 0.64cvss 9.8epss 0.01
Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/clientStatus.php?client_id=.
- risk 0.64cvss 9.8epss 0.01
Money Transfer Management System 1.0 is vulnerable to SQL Injection via /mtms/classes/Users.php?f=delete.
- risk 0.64cvss 9.8epss 0.01
Money Transfer Management System 1.0 is vulnerable to SQL Injection via \mtms\classes\Master.php?f=delete_transaction.
- risk 0.64cvss 9.8epss 0.01
Money Transfer Management System 1.0 is vulnerable to SQL Injection via \mtms\classes\Master.php?f=delete_fee.
- risk 0.64cvss 9.8epss 0.01
Money Transfer Management System 1.0 is vulnerable to SQL Injection via /mtms/admin/?page=user/manage_user&id=.
- risk 0.64cvss 9.8epss 0.01
Money Transfer Management System 1.0 is vulnerable to SQL Injection via /mtms/admin/?page=transaction/send&id=, id.
- risk 0.64cvss 9.8epss 0.01
IonizeCMS v1.0.8.1 was discovered to contain a SQL injection vulnerability via the id_page parameter in application/models/article_model.php.