VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 126 of 1,043
  • CVE-2022-0771CriMay 2, 2022
    risk 0.64cvss 9.8epss 0.02

    The SiteSuperCharger WordPress plugin before 5.2.0 does not validate, sanitise and escape various user inputs before using them in SQL statements via AJAX actions (available to both unauthenticated and authenticated users), leading to Unauthenticated SQL Injections

  • CVE-2022-27466CriMay 2, 2022
    risk 0.64cvss 9.8epss 0.02

    MCMS v5.2.27 was discovered to contain a SQL injection vulnerability in the orderBy parameter at /dict/list.do.

  • CVE-2022-28524CriApr 26, 2022
    risk 0.64cvss 9.8epss 0.01

    ED01-CMS v20180505 was discovered to contain a SQL injection vulnerability via the component post.php.

  • CVE-2022-27985CriApr 26, 2022
    risk 0.64cvss 9.8epss 0.07

    CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.

  • CVE-2022-27984CriApr 26, 2022
    risk 0.64cvss 9.8epss 0.07

    CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.

  • CVE-2022-27299CriApr 26, 2022
    risk 0.64cvss 9.8epss 0.02

    Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the component room.php.

  • CVE-2022-0782CriApr 25, 2022
    risk 0.64cvss 9.8epss 0.02

    The Donations WordPress plugin through 1.8 does not sanitise and escape the nd_donations_id parameter before using it in a SQL statement via the nd_donations_single_cause_form_validate_fields_php_function AJAX action (available to unauthenticated users), leading to an…

  • CVE-2022-0769CriApr 25, 2022
    risk 0.64cvss 9.8epss 0.08

    The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it is being interpolated in an SQL statement and then executed via the rating_vote AJAX action (available to both unauthenticated and authenticated users),…

  • CVE-2022-0693CriApr 25, 2022
    risk 0.64cvss 9.8epss 0.07

    The Master Elements WordPress plugin through 8.0 does not validate and escape the meta_ids parameter of its remove_post_meta_condition AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL…

  • CVE-2022-0657CriApr 25, 2022
    risk 0.64cvss 9.8epss 0.02

    The 5 Stars Rating Funnel WordPress Plugin | RRatingg WordPress plugin before 1.2.54 does not properly sanitise, validate and escape lead ids before using them in a SQL statement via the rrtngg_delete_leads AJAX action, available to unauthenticated users, leading to an…

  • CVE-2022-27342CriApr 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Link-Admin v0.0.1 was discovered to contain a SQL injection vulnerability via DictRest.ResponseResult().

  • CVE-2022-27341CriApr 22, 2022
    risk 0.64cvss 9.8epss 0.01

    JFinalCMS v2.0 was discovered to contain a SQL injection vulnerability via the Article Management function.

  • CVE-2022-28439CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&&action=delete&userid=4.

  • CVE-2022-28438CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=type&userrole=User&userid=.

  • CVE-2022-28437CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=type&userrole=Admin&userid=3.

  • CVE-2022-28436CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=display&value=Hide&userid=.

  • CVE-2022-28435CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/siteoptions.php&action=displaygoal&value=1&roleid=1.

  • CVE-2022-28434CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin.php?id=siteoptions&social=edit&sid=2.

  • CVE-2022-28433CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=display&value=Show&userid=.

  • CVE-2022-28432CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin.php?id=siteoptions&social=display&value=0&sid=2.