CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,856)
page 256 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-43521 | Hig | 0.57 | 8.8 | 0.01 | Jan 5, 2023 | Multiple vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the Aruba EdgeConnect Enterprise Orchestrator instance. An attacker could exploit… | ||
| CVE-2022-43520 | Hig | 0.57 | 8.8 | 0.01 | Jan 5, 2023 | Multiple vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the Aruba EdgeConnect Enterprise Orchestrator instance. An attacker could exploit… | ||
| CVE-2022-43519 | Hig | 0.57 | 8.8 | 0.01 | Jan 5, 2023 | Multiple vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the Aruba EdgeConnect Enterprise Orchestrator instance. An attacker could exploit… | ||
| CVE-2022-43437 | Hig | 0.57 | 8.8 | 0.01 | Jan 3, 2023 | The Download function’s parameter of EasyTest has insufficient validation for user input. A remote attacker authenticated as a general user can inject arbitrary SQL command to access, modify or delete database. | ||
| CVE-2022-46763 | Hig | 0.57 | 8.8 | 0.01 | Dec 27, 2022 | A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows a low-privileged database user to execute arbitrary SQL commands as the database administrator, resulting in execution of arbitrary code. | ||
| CVE-2022-3915 | Cri | 0.57 | 9.8 | 0.01 | Dec 12, 2022 | The Dokan WordPress plugin before 3.7.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users | ||
| CVE-2022-3751 | Cri | 0.57 | 9.8 | 0.01 | Nov 29, 2022 | SQL Injection in GitHub repository owncast/owncast prior to 0.0.13. | ||
| CVE-2022-3848 | Hig | 0.57 | 8.8 | 0.01 | Nov 28, 2022 | The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as admin | ||
| CVE-2022-3768 | Hig | 0.57 | 8.8 | 0.04 | Nov 28, 2022 | The WPSmartContracts WordPress plugin before 1.3.12 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as author | ||
| CVE-2022-45207 | Cri | 0.57 | 9.8 | 0.01 | Nov 25, 2022 | Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString. | ||
| CVE-2022-45206 | Cri | 0.57 | 9.8 | 0.01 | Nov 25, 2022 | Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check. | ||
| CVE-2022-45278 | Hig | 0.57 | 8.8 | 0.01 | Nov 23, 2022 | Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /index.php/admins/Fields/get_fields.html component. | ||
| CVE-2022-44140 | Hig | 0.57 | 8.8 | 0.01 | Nov 23, 2022 | Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /Member/memberedit.html component. | ||
| CVE-2022-42098 | Hig | 0.57 | 8.8 | 0.01 | Nov 22, 2022 | KLiK SocialMediaWebsite version v1.0.1 is vulnerable to SQL Injection via the profile.php. | ||
| CVE-2022-38148 | Hig | 0.57 | 8.8 | 0.01 | Nov 21, 2022 | Silverstripe silverstripe/framework through 4.11 allows SQL Injection. | ||
| CVE-2022-4093 | Cri | 0.57 | 9.8 | 0.04 | Nov 21, 2022 | SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or personal user information. Many high-profile data breaches in recent years have been the result of SQL injection attacks, leading to reputational damage and… | ||
| CVE-2022-43506 | Hig | 0.57 | 8.8 | 0.01 | Nov 17, 2022 | SQL Injection in HandlerTag_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network | ||
| CVE-2022-43457 | Hig | 0.57 | 8.8 | 0.01 | Nov 17, 2022 | SQL Injection in HandlerPage_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network | ||
| CVE-2022-43447 | Hig | 0.57 | 8.8 | 0.01 | Nov 17, 2022 | SQL Injection in AM_EBillAnalysis.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network | ||
| CVE-2022-41775 | Hig | 0.57 | 8.8 | 0.01 | Nov 17, 2022 | SQL Injection in Handler_CFG.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network |
- risk 0.57cvss 8.8epss 0.01
Multiple vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the Aruba EdgeConnect Enterprise Orchestrator instance. An attacker could exploit…
- risk 0.57cvss 8.8epss 0.01
Multiple vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the Aruba EdgeConnect Enterprise Orchestrator instance. An attacker could exploit…
- risk 0.57cvss 8.8epss 0.01
Multiple vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the Aruba EdgeConnect Enterprise Orchestrator instance. An attacker could exploit…
- risk 0.57cvss 8.8epss 0.01
The Download function’s parameter of EasyTest has insufficient validation for user input. A remote attacker authenticated as a general user can inject arbitrary SQL command to access, modify or delete database.
- risk 0.57cvss 8.8epss 0.01
A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows a low-privileged database user to execute arbitrary SQL commands as the database administrator, resulting in execution of arbitrary code.
- risk 0.57cvss 9.8epss 0.01
The Dokan WordPress plugin before 3.7.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users
- risk 0.57cvss 9.8epss 0.01
SQL Injection in GitHub repository owncast/owncast prior to 0.0.13.
- risk 0.57cvss 8.8epss 0.01
The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as admin
- risk 0.57cvss 8.8epss 0.04
The WPSmartContracts WordPress plugin before 1.3.12 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as author
- risk 0.57cvss 9.8epss 0.01
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString.
- risk 0.57cvss 9.8epss 0.01
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check.
- risk 0.57cvss 8.8epss 0.01
Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /index.php/admins/Fields/get_fields.html component.
- risk 0.57cvss 8.8epss 0.01
Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /Member/memberedit.html component.
- risk 0.57cvss 8.8epss 0.01
KLiK SocialMediaWebsite version v1.0.1 is vulnerable to SQL Injection via the profile.php.
- risk 0.57cvss 8.8epss 0.01
Silverstripe silverstripe/framework through 4.11 allows SQL Injection.
- risk 0.57cvss 9.8epss 0.04
SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or personal user information. Many high-profile data breaches in recent years have been the result of SQL injection attacks, leading to reputational damage and…
- risk 0.57cvss 8.8epss 0.01
SQL Injection in HandlerTag_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network
- risk 0.57cvss 8.8epss 0.01
SQL Injection in HandlerPage_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network
- risk 0.57cvss 8.8epss 0.01
SQL Injection in AM_EBillAnalysis.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network
- risk 0.57cvss 8.8epss 0.01
SQL Injection in Handler_CFG.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network