CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,856)
page 258 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-23695 | Hig | 0.57 | 8.8 | 0.01 | Sep 20, 2022 | Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify… | ||
| CVE-2022-23694 | Hig | 0.57 | 8.8 | 0.01 | Sep 20, 2022 | Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify… | ||
| CVE-2022-23693 | Hig | 0.57 | 8.8 | 0.01 | Sep 20, 2022 | Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify… | ||
| CVE-2022-23692 | Hig | 0.57 | 8.8 | 0.01 | Sep 20, 2022 | Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify… | ||
| CVE-2022-37205 | Hig | 0.57 | 8.8 | 0.02 | Sep 20, 2022 | JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection. | ||
| CVE-2022-23767 | Hig | 0.57 | 8.8 | 0.01 | Sep 19, 2022 | This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also identified during file transfer. An attacker can take advantage of these vulnerabilities to perform various attacks such as obtaining privileges and executing… | ||
| CVE-2022-38618 | Hig | 0.57 | 8.8 | 0.01 | Sep 19, 2022 | SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/country_group.jsf. | ||
| CVE-2022-2958 | Hig | 0.57 | 8.8 | 0.01 | Sep 19, 2022 | The BadgeOS WordPress plugin before 3.7.1.3 does not sanitise and escape parameters before using them in SQL statements via AJAX actions available to any authenticated users, leading to SQL Injections | ||
| CVE-2022-38617 | Hig | 0.57 | 8.8 | 0.01 | Sep 19, 2022 | SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the voiceAudit:j_id97 parameter at /SVFE2/pages/audit/voiceaudit.jsf. | ||
| CVE-2022-38808 | Hig | 0.57 | 8.8 | 0.01 | Sep 16, 2022 | ywoa v6.1 is vulnerable to SQL Injection via backend/oa/visual/exportExcel.do interface. | ||
| CVE-2022-37201 | Hig | 0.57 | 8.8 | 0.02 | Sep 15, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection. | ||
| CVE-2022-37207 | Hig | 0.57 | 8.8 | 0.02 | Sep 15, 2022 | JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection | ||
| CVE-2022-39817 | Hig | 0.57 | 8.8 | 0.01 | Sep 13, 2022 | In NOKIA 1350 OMS R14.2, multiple SQL Injection vulnerabilities occurs. Exploitation requires an authenticated attacker. Through the injection of arbitrary SQL statements, a potential authenticated attacker can modify query syntax and perform unauthorized (and unexpected)… | ||
| CVE-2022-34700 | Hig | 0.57 | 8.8 | 0.04 | Sep 13, 2022 | Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability | ||
| CVE-2022-38616 | Hig | 0.57 | 8.8 | 0.01 | Sep 13, 2022 | SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /feegroups/tgrt_group.jsf. | ||
| CVE-2022-38615 | Hig | 0.57 | 8.8 | 0.01 | Sep 9, 2022 | SmartVista SVFE2 v2.2.22 was discovered to contain multiple SQL injection vulnerabilities via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/service_group.jsf. | ||
| CVE-2022-36636 | Hig | 0.57 | 8.8 | 0.01 | Sep 2, 2022 | Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /print.php. | ||
| CVE-2022-38118 | Hig | 0.57 | 8.8 | 0.02 | Aug 30, 2022 | OAKlouds Portal website’s Meeting Room has insufficient validation for user input. A remote attacker with general user privilege can perform SQL-injection to access, modify, delete database, perform system operations and disrupt service. | ||
| CVE-2022-36690 | Hig | 0.57 | 8.8 | 0.01 | Aug 29, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user&id=. | ||
| CVE-2022-36689 | Hig | 0.57 | 8.8 | 0.01 | Aug 29, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /admin/?page=reports/waste&month=. |
- risk 0.57cvss 8.8epss 0.01
Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify…
- risk 0.57cvss 8.8epss 0.01
Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify…
- risk 0.57cvss 8.8epss 0.01
Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify…
- risk 0.57cvss 8.8epss 0.01
Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify…
- risk 0.57cvss 8.8epss 0.02
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
- risk 0.57cvss 8.8epss 0.01
This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also identified during file transfer. An attacker can take advantage of these vulnerabilities to perform various attacks such as obtaining privileges and executing…
- risk 0.57cvss 8.8epss 0.01
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/country_group.jsf.
- risk 0.57cvss 8.8epss 0.01
The BadgeOS WordPress plugin before 3.7.1.3 does not sanitise and escape parameters before using them in SQL statements via AJAX actions available to any authenticated users, leading to SQL Injections
- risk 0.57cvss 8.8epss 0.01
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the voiceAudit:j_id97 parameter at /SVFE2/pages/audit/voiceaudit.jsf.
- risk 0.57cvss 8.8epss 0.01
ywoa v6.1 is vulnerable to SQL Injection via backend/oa/visual/exportExcel.do interface.
- risk 0.57cvss 8.8epss 0.02
JFinal CMS 5.1.0 is vulnerable to SQL Injection.
- risk 0.57cvss 8.8epss 0.02
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection
- risk 0.57cvss 8.8epss 0.01
In NOKIA 1350 OMS R14.2, multiple SQL Injection vulnerabilities occurs. Exploitation requires an authenticated attacker. Through the injection of arbitrary SQL statements, a potential authenticated attacker can modify query syntax and perform unauthorized (and unexpected)…
- risk 0.57cvss 8.8epss 0.04
Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.01
SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /feegroups/tgrt_group.jsf.
- risk 0.57cvss 8.8epss 0.01
SmartVista SVFE2 v2.2.22 was discovered to contain multiple SQL injection vulnerabilities via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/service_group.jsf.
- risk 0.57cvss 8.8epss 0.01
Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /print.php.
- risk 0.57cvss 8.8epss 0.02
OAKlouds Portal website’s Meeting Room has insufficient validation for user input. A remote attacker with general user privilege can perform SQL-injection to access, modify, delete database, perform system operations and disrupt service.
- risk 0.57cvss 8.8epss 0.01
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user&id=.
- risk 0.57cvss 8.8epss 0.01
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /admin/?page=reports/waste&month=.