VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,856)

page 262 of 1,043
  • CVE-2022-22495HigMay 24, 2022
    risk 0.57cvss 8.8epss 0.02

    IBM i 7.3, 7.4, and 7.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 226941.

  • CVE-2022-30843HigMay 24, 2022
    risk 0.57cvss 8.8epss 0.01

    Room-rent-portal-site v1.0 is vulnerable to SQL Injection via /rrps/classes/Master.php?f=delete_category, id.

  • CVE-2022-30463HigMay 24, 2022
    risk 0.57cvss 8.8epss 0.01

    Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/classes/Master.php?f=delete_product.

  • CVE-2022-30459HigMay 24, 2022
    risk 0.57cvss 8.8epss 0.01

    ChatBot App with Suggestion in PHP/OOP v1.0 is vulnerable to SQL Injection via /simple_chat_bot/classes/Master.php?f=delete_response, id.

  • CVE-2021-42655HigMay 24, 2022
    risk 0.57cvss 8.8epss 0.01

    SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability.

  • CVE-2022-29304HigMay 19, 2022
    risk 0.57cvss 8.8epss 0.01

    Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /classes/master.php?f=delete_ Facility.

  • CVE-2022-28961HigMay 19, 2022
    risk 0.57cvss 8.8epss 0.02

    Spip Web Framework v3.1.13 and below was discovered to contain multiple SQL injection vulnerabilities at /ecrire via the lier_trad and where parameters.

  • CVE-2022-30599CriMay 18, 2022
    risk 0.57cvss 9.8epss 0.01

    A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.

  • CVE-2022-24391HigMay 17, 2022
    risk 0.57cvss 8.8epss 0.01

    Vulnerability in Fidelis Network and Deception CommandPost enables SQL injection through the web interface by an attacker with user level access. The vulnerability is present in Fidelis Network and Deception versions prior to 9.4.5. Patches and updates are available to address…

  • CVE-2022-1182HigMay 16, 2022
    risk 0.57cvss 8.8epss 0.01

    The Visual Slide Box Builder WordPress plugin through 3.2.9 does not sanitise and escape various parameters before using them in SQL statements via some of its AJAX actions available to any authenticated users (such as subscriber), leading to SQL Injections

  • CVE-2022-30765CriMay 16, 2022
    risk 0.57cvss 9.8epss 0.01

    Calibre-Web before 0.6.18 allows user table SQL Injection.

  • CVE-2021-41965HigMay 15, 2022
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability exists in ChurchCRM version 2.0.0 to 4.4.5 that allows an authenticated attacker to issue an arbitrary SQL command to the database through the unsanitized EN_tyid, theID and EID fields used when an Edit action on an existing record is being…

  • CVE-2022-30451HigMay 11, 2022
    risk 0.57cvss 8.8epss 0.02

    An authenticated user could execute code via a SQLi vulnerability in waimairenCMS before version 9.1.

  • CVE-2022-1453CriMay 10, 2022
    risk 0.57cvss 9.8epss 0.07

    The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-util.php file. This makes it possible for unauthenticated attackers to steal sensitive…

  • CVE-2020-19217HigMay 6, 2022
    risk 0.57cvss 8.8epss 0.01

    SQL Injection vulnerability in admin/batch_manager.php in piwigo v2.9.5, via the filter_category parameter to admin.php?page=batch_manager.

  • CVE-2020-19216HigMay 6, 2022
    risk 0.57cvss 8.8epss 0.01

    SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=group_perm.

  • CVE-2020-19215HigMay 6, 2022
    risk 0.57cvss 8.8epss 0.01

    SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=user_perm.

  • CVE-2022-29938HigMay 5, 2022
    risk 0.57cvss 8.8epss 0.01

    In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameter payment_id in interface\billing\new_payment.php via interface\billing\payment_master.inc.php leads to SQL injection.

  • CVE-2022-28552HigMay 4, 2022
    risk 0.57cvss 8.8epss 0.01

    Cscms 4.1 is vulnerable to SQL Injection. Log into the background, open the song module, create a new song, delete it to the recycle bin, and SQL injection security problems will occur when emptying the recycle bin.

  • CVE-2022-28099HigMay 4, 2022
    risk 0.57cvss 8.8epss 0.02

    Poultry Farm Management System v1.0 was discovered to contain a SQL injection vulnerability via the Item parameter at /farm/store.php.