VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,856)

page 216 of 1,043
  • CVE-2024-36840CriJun 12, 2024
    risk 0.59cvss 9.1epss 0.02

    SQL Injection vulnerability in Boelter Blue System Management v.1.3 allows a remote attacker to execute arbitrary code and obtain sensitive information via the id parameter to news_details.php and location_details.php; and the section parameter to services.php.

  • CVE-2024-34987CriJun 3, 2024
    risk 0.59cvss 9.1epss 0.01

    A SQL Injection vulnerability exists in the `ofrs/admin/index.php` script of PHPGurukul Online Fire Reporting System 1.2. The vulnerability allows attackers to bypass authentication and gain unauthorized access by injecting SQL commands into the username input field during the…

  • CVE-2024-5314CriMay 24, 2024
    risk 0.59cvss 9.1epss 0.01

    Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters…

  • CVE-2024-33146CriMay 7, 2024
    risk 0.59cvss 9.1epss 0.01

    J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the export function.

  • CVE-2024-27574CriApr 22, 2024
    risk 0.59cvss 9.1epss 0.01

    SQL Injection vulnerability in Trainme Academy version Ichin v.1.3.2 allows a remote attacker to obtain sensitive information via the informacion, idcurso, and tit parameters.

  • CVE-2024-31547CriApr 19, 2024
    risk 0.59cvss 9.1epss 0.01

    Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/item/view_item.php.

  • CVE-2022-43216CriApr 8, 2024
    risk 0.59cvss 9.1epss 0.00

    AbrhilSoft Employee's Portal before v5.6.2 was discovered to contain a SQL injection vulnerability in the login page.

  • CVE-2024-25867CriFeb 28, 2024
    risk 0.59cvss 9.1epss 0.01

    A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commands via the membershipType and membershipAmount parameters in the add_type.php component.

  • CVE-2024-25893CriFeb 21, 2024
    risk 0.59cvss 9.1epss 0.00

    ChurchCRM 5.5.0 FRCertificates.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.

  • CVE-2023-50429CriDec 9, 2023
    risk 0.59cvss 9.1epss 0.01

    IzyBat Orange casiers before 20230803_1 allows getEnsemble.php ensemble SQL injection.

  • CVE-2023-43909CriSep 29, 2023
    risk 0.59cvss 9.1epss 0.01

    Hospital Management System thru commit 4770d was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php.

  • CVE-2023-41387CriSep 19, 2023
    risk 0.59cvss 9.1epss 0.01

    A SQL injection in the flutter_downloader component through 1.11.1 for iOS allows remote attackers to steal session tokens and overwrite arbitrary files inside the app's container. The internal database of the framework is exposed to the local user if an app uses…

  • CVE-2023-39939CriAug 21, 2023
    risk 0.59cvss 9.1epss 0.01

    SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version) allows a remote unauthenticated attacker to execute arbitrary queries against the database and obtain or alter the information in it.

  • CVE-2023-36808HigJul 5, 2023
    risk 0.59cvss 8.6epss 0.52

    GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.8, Computer Virtual Machine form and GLPI inventory request can be used to perform a SQL injection attack. Version 10.0.8 has a patch for this issue. As a workaround, one…

  • CVE-2023-36932HigJul 5, 2023
    risk 0.59cvss 8.1epss 0.81

    In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), multiple SQL injection vulnerabilities have been identified in the MOVEit Transfer web application that could allow an…

  • CVE-2022-44580CriMar 15, 2023
    risk 0.59cvss 9.1epss 0.01

    SQL Injection (SQLi) vulnerability in RichPlugins Plugin for Google Reviews plugin <= 2.2.3 versions.

  • CVE-2023-23459CriFeb 15, 2023
    risk 0.59cvss 9.1epss 0.01

    Priority Windows may allow Command Execution via SQL Injection using an unspecified method.

  • CVE-2021-36434CriFeb 3, 2023
    risk 0.59cvss 9.1epss 0.01

    SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_json_check function in jocms/apps/mask/inc/getmask.php.

  • CVE-2021-36433CriFeb 3, 2023
    risk 0.59cvss 9.1epss 0.01

    SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_delete_mask function in jocms/apps/mask/mask.php.

  • CVE-2021-36431CriFeb 3, 2023
    risk 0.59cvss 9.1epss 0.01

    SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_json_check() function in jocms/apps/mask/inc/mask.php.