VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,856)

page 246 of 1,043
  • CVE-2024-1893HigApr 9, 2024
    risk 0.57cvss 8.8epss 0.01

    The Easy Property Listings plugin for WordPress is vulnerable to time-based SQL Injection via the ‘property_status’ shortcode attribute in all versions up to, and including, 3.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…

  • CVE-2023-6967HigApr 9, 2024
    risk 0.57cvss 8.8epss 0.01

    The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2) due to insufficient escaping on the user supplied parameter and lack…

  • CVE-2024-30862HigApr 1, 2024
    risk 0.57cvss 8.8epss 0.01

    netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /3g/index.php.

  • CVE-2024-30860HigApr 1, 2024
    risk 0.57cvss 8.8epss 0.01

    netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/export_excel_user.php.

  • CVE-2024-30859HigApr 1, 2024
    risk 0.57cvss 8.8epss 0.01

    netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/config_ISCGroupSSLCert.php.

  • CVE-2024-30871HigApr 1, 2024
    risk 0.57cvss 8.8epss 0.01

    netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /WebPages/applyhardware.php.

  • CVE-2024-30870HigApr 1, 2024
    risk 0.57cvss 8.8epss 0.01

    netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/address_interpret.php.

  • CVE-2024-28559HigMar 22, 2024
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the setPrice() function of the Goodsbatchset.php component.

  • CVE-2024-1799HigMar 20, 2024
    risk 0.57cvss 8.8epss 0.01

    The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to SQL Injection via the 'achievement_types' attribute of the gamipress_earnings shortcode in all versions up to, and including, 6.8.6 due…

  • CVE-2024-1795HigMar 15, 2024
    risk 0.57cvss 8.8epss 0.01

    The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to SQL Injection via the 'name' parameter in the woof shortcode in all versions up to, and including, 1.3.5.2 due to insufficient escaping on the user supplied parameter and lack of…

  • CVE-2023-41504HigMar 13, 2024
    risk 0.57cvss 8.8epss 0.01

    SQL Injection vulnerability in Student Enrollment In PHP 1.0 allows attackers to run arbitrary code via the Student Search function.

  • CVE-2024-1751HigMar 13, 2024
    risk 0.57cvss 8.8epss 0.03

    The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the question_id parameter in all versions up to, and including, 2.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2024-1203HigMar 13, 2024
    risk 0.57cvss 8.8epss 0.01

    The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'valueData' parameter in all versions up to, and including, 7.0.7 due to insufficient escaping on the user supplied…

  • CVE-2022-46499HigMar 7, 2024
    risk 0.57cvss 8.8epss 0.01

    Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_admin_view_single_patient.php.

  • CVE-2024-28094HigMar 7, 2024
    risk 0.57cvss 8.8epss 0.01

    Chat functionality in Schoolbox application before version 23.1.3 is vulnerable to blind SQL Injection enabling the authenticated attackers to read, modify, and delete database records.

  • CVE-2024-27304CriMar 6, 2024
    risk 0.57cvss 9.8epss 0.01

    pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the…

  • CVE-2023-49548HigMar 5, 2024
    risk 0.57cvss 8.8epss 0.01

    Customer Support System v1 was discovered to contain a SQL injection vulnerability via the lastname parameter at /customer_support/ajax.php?action=save_user.

  • CVE-2023-49546HigMar 5, 2024
    risk 0.57cvss 8.8epss 0.01

    Customer Support System v1 was discovered to contain a SQL injection vulnerability via the email parameter at /customer_support/ajax.php.

  • CVE-2024-25866HigFeb 28, 2024
    risk 0.57cvss 8.8epss 0.01

    A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commands via the email parameter in the index.php component.

  • CVE-2024-0786HigFeb 28, 2024
    risk 0.57cvss 8.8epss 0.01

    The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the ee_syncProductCategory function using the parameters conditionData, valueData, productArray, exclude and…