VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,856)

page 247 of 1,043
  • CVE-2024-24310HigFeb 23, 2024
    risk 0.57cvss 8.8epss 0.01

    In the module "Generate barcode on invoice / delivery slip" (ecgeneratebarcode) from Ether Creation <= 1.2.0 for PrestaShop, a guest can perform SQL injection.

  • CVE-2024-26262HigFeb 15, 2024
    risk 0.57cvss 8.8epss 0.01

    EBM Technologies Uniweb/SoliPACS WebServer's query functionality lacks proper restrictions of user input, allowing remote attackers authenticated as regular user to inject SQL commands for reading, modifying, and deleting database records, as well as executing system commands.…

  • CVE-2024-1523HigFeb 15, 2024
    risk 0.57cvss 8.8epss 0.01

    EC-WEB FS-EZViewer(Web)'s query functionality lacks proper restrictions of user input, allowing remote attackers authenticated as regular user to inject SQL commands for reading, modifying, and deleting database records, as well as executing system commands. Attackers may even…

  • CVE-2024-23810HigFeb 13, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application is vulnerable to SQL injection. This could allow an unauthenticated remote attacker to execute arbitrary SQL queries on the server database.

  • CVE-2024-0594HigFeb 10, 2024
    risk 0.57cvss 8.8epss 0.01

    The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to union-based SQL Injection via the 'q' parameter of the wpas_get_users action in all versions up to, and including, 6.1.7 due to insufficient escaping on the user supplied parameter…

  • CVE-2024-25318HigFeb 9, 2024
    risk 0.57cvss 8.8epss 0.01

    Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'pid' parameter in Hotel/admin/print.php?pid=2.

  • CVE-2024-25310HigFeb 9, 2024
    risk 0.57cvss 8.8epss 0.01

    Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/delete.php?id=5."

  • CVE-2024-25312HigFeb 9, 2024
    risk 0.57cvss 8.8epss 0.01

    Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/sub_delete.php?id=5."

  • CVE-2024-25309HigFeb 9, 2024
    risk 0.57cvss 8.8epss 0.01

    Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'pass' parameter at School/teacher_login.php.

  • CVE-2024-25308HigFeb 9, 2024
    risk 0.57cvss 8.8epss 0.01

    Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'name' parameter at School/teacher_login.php.

  • CVE-2024-25306HigFeb 9, 2024
    risk 0.57cvss 8.8epss 0.01

    Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'aname' parameter at "School/index.php".

  • CVE-2024-25305HigFeb 9, 2024
    risk 0.57cvss 8.8epss 0.01

    Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at School/index.php.

  • CVE-2024-25304HigFeb 9, 2024
    risk 0.57cvss 8.8epss 0.01

    Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'apass' parameter at "School/index.php."

  • CVE-2024-24811CriFeb 7, 2024
    risk 0.57cvss 9.8epss 0.01

    SQLAlchemyDA is a generic database adapter for ZSQL methods. A vulnerability found in versions prior to 2.2 allows unauthenticated execution of arbitrary SQL statements on the database to which the SQLAlchemyDA instance is connected. All users are affected. The problem has been…

  • CVE-2023-47568HigFeb 2, 2024
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following versions: QTS…

  • CVE-2024-1061HigJan 30, 2024
    risk 0.57cvss 8.6epss 0.11

    The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' parameter in the  'get_view' function.

  • CVE-2023-5041HigJan 17, 2024
    risk 0.57cvss 8.8epss 0.01

    The Track The Click WordPress plugin before 0.3.12 does not properly sanitize query parameters to the stats REST endpoint before using them in a database query, allowing a logged in user with an author role or higher to perform time based blind SQLi attacks on the database.

  • CVE-2023-6373HigJan 16, 2024
    risk 0.57cvss 8.8epss 0.00

    The ArtPlacer Widget WordPress plugin before 2.20.7 does not sanitize and escape the "id" parameter before submitting the query, leading to a SQLI exploitable by editors and above. Note: Due to the lack of CSRF check, the issue could also be exploited via a CSRF against a logged…

  • CVE-2021-24869HigJan 16, 2024
    risk 0.57cvss 8.8epss 0.01

    The WP Fastest Cache WordPress plugin before 0.9.5 does not escape user input in the set_urls_with_terms method before using it in a SQL statement, leading to an SQL injection exploitable by low privilege users such as subscriber

  • CVE-2023-47460HigJan 16, 2024
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability in Knovos Discovery v.22.67.0 allows a remote attacker to execute arbitrary code via the /DiscoveryProcess/Service/Admin.svc/getGridColumnStructure component.