CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,856)
page 216 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-36840 | Cri | 0.59 | 9.1 | 0.02 | Jun 12, 2024 | SQL Injection vulnerability in Boelter Blue System Management v.1.3 allows a remote attacker to execute arbitrary code and obtain sensitive information via the id parameter to news_details.php and location_details.php; and the section parameter to services.php. | ||
| CVE-2024-34987 | Cri | 0.59 | 9.1 | 0.01 | Jun 3, 2024 | A SQL Injection vulnerability exists in the `ofrs/admin/index.php` script of PHPGurukul Online Fire Reporting System 1.2. The vulnerability allows attackers to bypass authentication and gain unauthorized access by injecting SQL commands into the username input field during the… | ||
| CVE-2024-5314 | Cri | 0.59 | 9.1 | 0.01 | May 24, 2024 | Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters… | ||
| CVE-2024-33146 | — | Cri | 0.59 | 9.1 | 0.01 | May 7, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the export function. | |
| CVE-2024-27574 | Cri | 0.59 | 9.1 | 0.01 | Apr 22, 2024 | SQL Injection vulnerability in Trainme Academy version Ichin v.1.3.2 allows a remote attacker to obtain sensitive information via the informacion, idcurso, and tit parameters. | ||
| CVE-2024-31547 | Cri | 0.59 | 9.1 | 0.01 | Apr 19, 2024 | Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/item/view_item.php. | ||
| CVE-2022-43216 | Cri | 0.59 | 9.1 | 0.00 | Apr 8, 2024 | AbrhilSoft Employee's Portal before v5.6.2 was discovered to contain a SQL injection vulnerability in the login page. | ||
| CVE-2024-25867 | Cri | 0.59 | 9.1 | 0.01 | Feb 28, 2024 | A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commands via the membershipType and membershipAmount parameters in the add_type.php component. | ||
| CVE-2024-25893 | Cri | 0.59 | 9.1 | 0.00 | Feb 21, 2024 | ChurchCRM 5.5.0 FRCertificates.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter. | ||
| CVE-2023-50429 | Cri | 0.59 | 9.1 | 0.01 | Dec 9, 2023 | IzyBat Orange casiers before 20230803_1 allows getEnsemble.php ensemble SQL injection. | ||
| CVE-2023-43909 | Cri | 0.59 | 9.1 | 0.01 | Sep 29, 2023 | Hospital Management System thru commit 4770d was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php. | ||
| CVE-2023-41387 | Cri | 0.59 | 9.1 | 0.01 | Sep 19, 2023 | A SQL injection in the flutter_downloader component through 1.11.1 for iOS allows remote attackers to steal session tokens and overwrite arbitrary files inside the app's container. The internal database of the framework is exposed to the local user if an app uses… | ||
| CVE-2023-39939 | Cri | 0.59 | 9.1 | 0.01 | Aug 21, 2023 | SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version) allows a remote unauthenticated attacker to execute arbitrary queries against the database and obtain or alter the information in it. | ||
| CVE-2023-36808 | Hig | 0.59 | 8.6 | 0.52 | Jul 5, 2023 | GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.8, Computer Virtual Machine form and GLPI inventory request can be used to perform a SQL injection attack. Version 10.0.8 has a patch for this issue. As a workaround, one… | ||
| CVE-2023-36932 | Hig | 0.59 | 8.1 | 0.81 | Jul 5, 2023 | In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), multiple SQL injection vulnerabilities have been identified in the MOVEit Transfer web application that could allow an… | ||
| CVE-2022-44580 | Cri | 0.59 | 9.1 | 0.01 | Mar 15, 2023 | SQL Injection (SQLi) vulnerability in RichPlugins Plugin for Google Reviews plugin <= 2.2.3 versions. | ||
| CVE-2023-23459 | Cri | 0.59 | 9.1 | 0.01 | Feb 15, 2023 | Priority Windows may allow Command Execution via SQL Injection using an unspecified method. | ||
| CVE-2021-36434 | Cri | 0.59 | 9.1 | 0.01 | Feb 3, 2023 | SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_json_check function in jocms/apps/mask/inc/getmask.php. | ||
| CVE-2021-36433 | Cri | 0.59 | 9.1 | 0.01 | Feb 3, 2023 | SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_delete_mask function in jocms/apps/mask/mask.php. | ||
| CVE-2021-36431 | Cri | 0.59 | 9.1 | 0.01 | Feb 3, 2023 | SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_json_check() function in jocms/apps/mask/inc/mask.php. |
- risk 0.59cvss 9.1epss 0.02
SQL Injection vulnerability in Boelter Blue System Management v.1.3 allows a remote attacker to execute arbitrary code and obtain sensitive information via the id parameter to news_details.php and location_details.php; and the section parameter to services.php.
- risk 0.59cvss 9.1epss 0.01
A SQL Injection vulnerability exists in the `ofrs/admin/index.php` script of PHPGurukul Online Fire Reporting System 1.2. The vulnerability allows attackers to bypass authentication and gain unauthorized access by injecting SQL commands into the username input field during the…
- risk 0.59cvss 9.1epss 0.01
Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters…
- risk 0.59cvss 9.1epss 0.01
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the export function.
- risk 0.59cvss 9.1epss 0.01
SQL Injection vulnerability in Trainme Academy version Ichin v.1.3.2 allows a remote attacker to obtain sensitive information via the informacion, idcurso, and tit parameters.
- risk 0.59cvss 9.1epss 0.01
Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/item/view_item.php.
- risk 0.59cvss 9.1epss 0.00
AbrhilSoft Employee's Portal before v5.6.2 was discovered to contain a SQL injection vulnerability in the login page.
- risk 0.59cvss 9.1epss 0.01
A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commands via the membershipType and membershipAmount parameters in the add_type.php component.
- risk 0.59cvss 9.1epss 0.00
ChurchCRM 5.5.0 FRCertificates.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.
- risk 0.59cvss 9.1epss 0.01
IzyBat Orange casiers before 20230803_1 allows getEnsemble.php ensemble SQL injection.
- risk 0.59cvss 9.1epss 0.01
Hospital Management System thru commit 4770d was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php.
- risk 0.59cvss 9.1epss 0.01
A SQL injection in the flutter_downloader component through 1.11.1 for iOS allows remote attackers to steal session tokens and overwrite arbitrary files inside the app's container. The internal database of the framework is exposed to the local user if an app uses…
- risk 0.59cvss 9.1epss 0.01
SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version) allows a remote unauthenticated attacker to execute arbitrary queries against the database and obtain or alter the information in it.
- risk 0.59cvss 8.6epss 0.52
GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.8, Computer Virtual Machine form and GLPI inventory request can be used to perform a SQL injection attack. Version 10.0.8 has a patch for this issue. As a workaround, one…
- risk 0.59cvss 8.1epss 0.81
In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), multiple SQL injection vulnerabilities have been identified in the MOVEit Transfer web application that could allow an…
- risk 0.59cvss 9.1epss 0.01
SQL Injection (SQLi) vulnerability in RichPlugins Plugin for Google Reviews plugin <= 2.2.3 versions.
- risk 0.59cvss 9.1epss 0.01
Priority Windows may allow Command Execution via SQL Injection using an unspecified method.
- risk 0.59cvss 9.1epss 0.01
SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_json_check function in jocms/apps/mask/inc/getmask.php.
- risk 0.59cvss 9.1epss 0.01
SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_delete_mask function in jocms/apps/mask/mask.php.
- risk 0.59cvss 9.1epss 0.01
SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_json_check() function in jocms/apps/mask/inc/mask.php.