VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,856)

page 255 of 1,043
  • CVE-2023-24654HigFeb 27, 2023
    risk 0.57cvss 8.8epss 0.01

    Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Request a Quote function.

  • CVE-2023-24653HigFeb 27, 2023
    risk 0.57cvss 8.8epss 0.01

    Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the oldpass parameter under the Change Password function.

  • CVE-2023-24652HigFeb 27, 2023
    risk 0.57cvss 8.8epss 0.01

    Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the Description parameter under the Create ticket function.

  • CVE-2023-24364HigFeb 27, 2023
    risk 0.57cvss 8.8epss 0.01

    Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter under the Admin Panel.

  • CVE-2023-26325HigFeb 23, 2023
    risk 0.57cvss 8.8epss 0.01

    The 'rx_export_review' action in the ReviewX WordPress Plugin, is affected by an authenticated SQL injection vulnerability in the 'filterValue' and 'selectedColumns' parameters.

  • CVE-2023-25158CriFeb 21, 2023
    risk 0.57cvss 9.8epss 0.01

    GeoTools is an open source Java library that provides tools for geospatial data. GeoTools includes support for OGC Filter expression language parsing, encoding and execution against a range of datastore. SQL Injection Vulnerabilities have been found when executing OGC Filters…

  • CVE-2022-38867HigFeb 15, 2023
    risk 0.57cvss 8.8epss 0.01

    SQL Injection vulnerability in rttys versions 4.0.0, 4.0.1, 4.0.2, and 4.4.x in api.go, allows attackers to execute arbitrary code.

  • CVE-2022-45090HigFeb 12, 2023
    risk 0.57cvss 8.8epss 0.01

    Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection. This issue affects Smartpower Web: before 23.01.01.

  • CVE-2022-45089HigFeb 12, 2023
    risk 0.57cvss 8.8epss 0.01

    Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection. This issue affects Smartpower Web: before 23.01.01.

  • CVE-2023-24956HigFeb 1, 2023
    risk 0.57cvss 8.8epss 0.01

    Forget Heart Message Box v1.1 was discovered to contain a SQL injection vulnerability via the name parameter at /cha.php.

  • CVE-2023-24163CriJan 31, 2023
    risk 0.57cvss 9.8epss 0.01

    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.

  • CVE-2020-22452CriJan 26, 2023
    risk 0.57cvss 9.8epss 0.02

    SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.

  • CVE-2023-23490HigJan 20, 2023
    risk 0.57cvss 8.8epss 0.02

    The Survey Maker WordPress Plugin, version < 3.1.2, is affected by an authenticated SQL injection vulnerability in the 'surveys_ids' parameter of its 'ays_surveys_export_json' action.

  • CVE-2021-26644HigJan 20, 2023
    risk 0.57cvss 8.8epss 0.01

    SQL-Injection vulnerability caused by the lack of verification of input values for the table name of DB used by the Mangboard bulletin board. A remote attacker can use this vulnerability to execute arbitrary code on the server where the bulletin board is running.

  • CVE-2022-47105CriJan 19, 2023
    risk 0.57cvss 9.8epss 0.01

    Jeecg-boot v3.4.4 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.

  • CVE-2023-22727CriJan 17, 2023
    risk 0.57cvss 9.8epss 0.01

    CakePHP is a development framework for PHP web apps. In affected versions the `Cake\Database\Query::limit()` and `Cake\Database\Query::offset()` methods are vulnerable to SQL injection if passed un-sanitized user request data. This issue has been fixed in 4.2.12, 4.3.11, 4.4.10.…

  • CVE-2022-43531HigJan 5, 2023
    risk 0.57cvss 8.8epss 0.01

    Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify…

  • CVE-2022-43530HigJan 5, 2023
    risk 0.57cvss 8.8epss 0.01

    Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify…

  • CVE-2022-43523HigJan 5, 2023
    risk 0.57cvss 8.8epss 0.01

    Multiple vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the Aruba EdgeConnect Enterprise Orchestrator instance. An attacker could exploit…

  • CVE-2022-43522HigJan 5, 2023
    risk 0.57cvss 8.8epss 0.01

    Multiple vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the Aruba EdgeConnect Enterprise Orchestrator instance. An attacker could exploit…