VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,856)

page 249 of 1,043
  • CVE-2023-46575CriNov 24, 2023
    risk 0.57cvss 9.8epss 0.01

    A SQL injection vulnerability exists in Meshery prior to version v0.6.179, enabling a remote attacker to retrieve sensitive information and execute arbitrary code through the “order” parameter

  • CVE-2023-37924CriNov 22, 2023
    risk 0.57cvss 9.8epss 0.07

    Apache Software Foundation Apache Submarine has an SQL injection vulnerability when a user logs in. This issue can result in unauthorized login. Now we have fixed this issue and now user must have the correct login to access workbench. This issue affects Apache Submarine: from…

  • CVE-2023-40923HigNov 15, 2023
    risk 0.57cvss 8.8epss 0.01

    MyPrestaModules ordersexport before v5.0 was discovered to contain multiple SQL injection vulnerabilities at send.php via the key and save_setting parameters.

  • CVE-2023-47609HigNov 14, 2023
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability in OSS Calendar versions prior to v.2.0.3 allows a remote authenticated attacker to execute arbitrary code or obtain and/or alter the information stored in the database by sending a specially crafted request.

  • CVE-2023-5709HigNov 7, 2023
    risk 0.57cvss 8.8epss 0.01

    The WD WidgetTwitter plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…

  • CVE-2023-45996HigOct 31, 2023
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability in Senayan Library Management Systems Slims v.9 and Bulian v.9.6.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script to the reborrowLimit parameter in the member_type.php.

  • CVE-2023-5315HigOct 30, 2023
    risk 0.57cvss 8.8epss 0.01

    The Google Maps made Simple plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 0.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…

  • CVE-2023-44480HigOct 27, 2023
    risk 0.57cvss 8.8epss 0.01

    Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setcasualleave' parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-38190HigOct 21, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Export SQL Injection via the size parameter.

  • CVE-2023-4999HigOct 20, 2023
    risk 0.57cvss 8.8epss 0.01

    The Horizontal scrolling announcement plugin for WordPress is vulnerable to SQL Injection via the plugin's [horizontal-scrolling] shortcode in versions up to, and including, 9.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…

  • CVE-2022-4290HigOct 20, 2023
    risk 0.57cvss 8.8epss 0.01

    The Cyr to Lat plugin for WordPress is vulnerable to authenticated SQL Injection via the 'ctl_sanitize_title' function in versions up to, and including, 3.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…

  • CVE-2023-4776HigOct 16, 2023
    risk 0.57cvss 8.8epss 0.01

    The School Management System WordPress plugin before 2.2.5 uses the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query, leading to a SQL injection exploitable by relatively low-privilege users like Teachers.

  • CVE-2023-2681HigOct 3, 2023
    risk 0.57cvss 8.8epss 0.01

    An SQL Injection vulnerability has been found on Jorani version 1.0.0. This vulnerability allows an authenticated remote user, with low privileges, to send queries with malicious SQL code on the "/leaves/validate" path and the “id” parameter, managing to extract arbritary…

  • CVE-2023-4103HigOct 3, 2023
    risk 0.57cvss 8.8epss 0.01

    QSige statistics are affected by a remote SQLi vulnerability. It has been identified that the web application does not correctly filter input parameters, allowing SQL injections, DoS or information disclosure. As a prerequisite, it is necessary to log into the application.

  • CVE-2023-4102HigOct 3, 2023
    risk 0.57cvss 8.8epss 0.01

    QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. As a prerequisite, it is necessary to log into the application.

  • CVE-2023-4098HigOct 3, 2023
    risk 0.57cvss 8.8epss 0.01

    It has been identified that the web application does not correctly filter input parameters, allowing SQL injections, DoS or information disclosure. As a prerequisite, it is necessary to log into the application.

  • CVE-2023-43014HigSep 28, 2023
    risk 0.57cvss 8.8epss 0.01

    Asset Management System v1.0 is vulnerable to an Authenticated SQL Injection vulnerability on the 'first_name' and 'last_name' parameters of user.php page, allowing an authenticated attacker to dump all the contents of the database contents.

  • CVE-2023-43192HigSep 27, 2023
    risk 0.57cvss 8.8epss 0.01

    SQL injection can exist in a newly created part of the SpringbootCMS 1.0 background, and the parameters submitted by users are not filtered. As a result, special characters in parameters destroy the original logic of SQL statements. Attackers can use this vulnerability to…

  • CVE-2023-43610HigSep 27, 2023
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor (without setting authority) or higher privilege to perform unintended database operations.

  • CVE-2023-39378HigSep 27, 2023
    risk 0.57cvss 8.8epss 0.01

    SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') by an unauthenticated user