CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 124 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-29748 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | Simple Client Management System 1.0 is vulnerable to SQL Injection via \cms\admin?page=client/manage_client&id=. | ||
| CVE-2022-29747 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=invoice/manage_invoice&id= // Leak place ---> id. | ||
| CVE-2022-30449 | Cri | 0.64 | 9.8 | 0.02 | May 11, 2022 | Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in room.php. | ||
| CVE-2022-30048 | Cri | 0.64 | 9.8 | 0.01 | May 11, 2022 | Mingsoft MCMS 5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/list URI via orderBy parameter. | ||
| CVE-2022-30047 | Cri | 0.64 | 9.8 | 0.01 | May 11, 2022 | Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/listExcludeApp URI via orderBy parameter. | ||
| CVE-2022-29656 | Cri | 0.64 | 9.8 | 0.01 | May 11, 2022 | Wedding Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Wedding-Management/package_detail.php. | ||
| CVE-2022-29317 | Cri | 0.64 | 9.8 | 0.01 | May 11, 2022 | Simple Bus Ticket Booking System v1.0 was discovered to contain multiple SQL injection vulnerbilities via the username and password parameters at /assets/partials/_handleLogin.php. | ||
| CVE-2022-29316 | Cri | 0.64 | 9.8 | 0.03 | May 11, 2022 | Complete Online Job Search System v1.0 was discovered to contain a SQL injection vulnerability via /eris/index.php?q=result&searchfor=advancesearch. | ||
| CVE-2022-1505 | Cri | 0.64 | 9.8 | 0.02 | May 10, 2022 | The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-api-endpoints.php file. This makes it possible for unauthenticated attackers to steal… | ||
| CVE-2022-28110 | Cri | 0.64 | 9.8 | 0.01 | May 10, 2022 | Hotel Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at the login page. | ||
| CVE-2021-43094 | Cri | 0.64 | 9.8 | 0.01 | May 10, 2022 | An SQL Injection vulnerability exists in OpenMRS Reference Application Standalone Edition <=2.11 and Platform Standalone Edition <=2.4.0 via GET requests on arbitrary parameters in patient.page. | ||
| CVE-2022-30335 | Cri | 0.64 | 9.8 | 0.01 | May 9, 2022 | Bonanza Wealth Management System (BWM) 7.3.2 allows SQL injection via the login form. Users who supply the application with a SQL injection payload in the User Name textbox could collect all passwords in encrypted format from the Microsoft SQL Server component. | ||
| CVE-2022-1013 | Cri | 0.64 | 9.8 | 0.07 | May 9, 2022 | The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to a blind SQL injection vulnerability. | ||
| CVE-2022-0948 | Cri | 0.64 | 9.8 | 0.10 | May 9, 2022 | The Order Listener for WooCommerce WordPress plugin before 3.2.2 does not sanitise and escape the id parameter before using it in a SQL statement via a REST route available to unauthenticated users, leading to an SQL injection | ||
| CVE-2022-0836 | Cri | 0.64 | 9.8 | 0.02 | May 9, 2022 | The SEMA API WordPress plugin before 4.02 does not properly sanitise and escape some parameters before using them in SQL statements via an AJAX action, leading to SQL Injections exploitable by unauthenticated users | ||
| CVE-2022-0826 | Cri | 0.64 | 9.8 | 0.09 | May 9, 2022 | The WP Video Gallery WordPress plugin through 1.7.1 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users | ||
| CVE-2022-0814 | Cri | 0.64 | 9.8 | 0.09 | May 9, 2022 | The Ubigeo de Perú para Woocommerce WordPress plugin before 3.6.4 does not properly sanitise and escape some parameters before using them in SQL statements via various AJAX actions, some of which are available to unauthenticated users, leading to SQL Injections | ||
| CVE-2022-0592 | Cri | 0.64 | 9.8 | 0.10 | May 9, 2022 | The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it in a SQL statement, leading to a SQL Injection exploitable by unauthenticated users. | ||
| CVE-2022-28163 | Cri | 0.64 | 9.8 | 0.01 | May 6, 2022 | In Brocade SANnav before Brocade SANnav 2.2.0, multiple endpoints associated with Zone management are susceptible to SQL injection, allowing an attacker to run arbitrary SQL commands. | ||
| CVE-2022-27360 | Cri | 0.64 | 9.8 | 0.02 | May 5, 2022 | SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment. |
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System 1.0 is vulnerable to SQL Injection via \cms\admin?page=client/manage_client&id=.
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=invoice/manage_invoice&id= // Leak place ---> id.
- risk 0.64cvss 9.8epss 0.02
Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in room.php.
- risk 0.64cvss 9.8epss 0.01
Mingsoft MCMS 5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/list URI via orderBy parameter.
- risk 0.64cvss 9.8epss 0.01
Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/listExcludeApp URI via orderBy parameter.
- risk 0.64cvss 9.8epss 0.01
Wedding Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Wedding-Management/package_detail.php.
- risk 0.64cvss 9.8epss 0.01
Simple Bus Ticket Booking System v1.0 was discovered to contain multiple SQL injection vulnerbilities via the username and password parameters at /assets/partials/_handleLogin.php.
- risk 0.64cvss 9.8epss 0.03
Complete Online Job Search System v1.0 was discovered to contain a SQL injection vulnerability via /eris/index.php?q=result&searchfor=advancesearch.
- risk 0.64cvss 9.8epss 0.02
The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-api-endpoints.php file. This makes it possible for unauthenticated attackers to steal…
- risk 0.64cvss 9.8epss 0.01
Hotel Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at the login page.
- risk 0.64cvss 9.8epss 0.01
An SQL Injection vulnerability exists in OpenMRS Reference Application Standalone Edition <=2.11 and Platform Standalone Edition <=2.4.0 via GET requests on arbitrary parameters in patient.page.
- risk 0.64cvss 9.8epss 0.01
Bonanza Wealth Management System (BWM) 7.3.2 allows SQL injection via the login form. Users who supply the application with a SQL injection payload in the User Name textbox could collect all passwords in encrypted format from the Microsoft SQL Server component.
- risk 0.64cvss 9.8epss 0.07
The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to a blind SQL injection vulnerability.
- risk 0.64cvss 9.8epss 0.10
The Order Listener for WooCommerce WordPress plugin before 3.2.2 does not sanitise and escape the id parameter before using it in a SQL statement via a REST route available to unauthenticated users, leading to an SQL injection
- risk 0.64cvss 9.8epss 0.02
The SEMA API WordPress plugin before 4.02 does not properly sanitise and escape some parameters before using them in SQL statements via an AJAX action, leading to SQL Injections exploitable by unauthenticated users
- risk 0.64cvss 9.8epss 0.09
The WP Video Gallery WordPress plugin through 1.7.1 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users
- risk 0.64cvss 9.8epss 0.09
The Ubigeo de Perú para Woocommerce WordPress plugin before 3.6.4 does not properly sanitise and escape some parameters before using them in SQL statements via various AJAX actions, some of which are available to unauthenticated users, leading to SQL Injections
- risk 0.64cvss 9.8epss 0.10
The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it in a SQL statement, leading to a SQL Injection exploitable by unauthenticated users.
- risk 0.64cvss 9.8epss 0.01
In Brocade SANnav before Brocade SANnav 2.2.0, multiple endpoints associated with Zone management are susceptible to SQL injection, allowing an attacker to run arbitrary SQL commands.
- risk 0.64cvss 9.8epss 0.02
SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment.