VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,856)

page 265 of 1,043
  • CVE-2022-0366HigFeb 2, 2022
    risk 0.57cvss 8.8epss 0.01

    An authenticated and authorized agent user could potentially gain administrative access via an SQLi vulnerability to Capsule8 Console between versions 4.6.0 and 4.9.1.

  • CVE-2021-24919HigFeb 1, 2022
    risk 0.57cvss 8.8epss 0.02

    The Wicked Folders WordPress plugin before 2.8.10 does not sanitise and escape the folder_id parameter before using it in a SQL statement in the wicked_folders_save_sort_order AJAX action, available to any authenticated user. leading to an SQL injection

  • CVE-2022-0362CriJan 26, 2022
    risk 0.57cvss 9.8epss 0.01

    SQL Injection in Packagist showdoc/showdoc prior to 2.10.3.

  • CVE-2021-46089CriJan 25, 2022
    risk 0.57cvss 9.8epss 0.02

    In JeecgBoot 3.0, there is a SQL injection vulnerability that can operate the database with root privileges.

  • CVE-2021-45803HigJan 25, 2022
    risk 0.57cvss 8.8epss 0.01

    MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because this view parameter value is added to the SQL query without additional verification when viewing reservation.

  • CVE-2021-45406HigJan 14, 2022
    risk 0.57cvss 8.8epss 0.02

    In SalonERP 3.0.1, a SQL injection vulnerability allows an attacker to inject payload using 'sql' parameter in SQL query while generating a report. Upon successfully discovering the login admin password hash, it can be decrypted to obtain the plain-text password.

  • CVE-2022-0224CriJan 14, 2022
    risk 0.57cvss 9.8epss 0.02

    dolibarr is vulnerable to Improper Neutralization of Special Elements used in an SQL Command

  • CVE-2021-43971HigJan 11, 2022
    risk 0.57cvss 8.8epss 0.02

    A SQL injection vulnerability in /mobile/SelectUsers.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to execute arbitrary SQL commands via the filterText parameter.

  • CVE-2021-37197HigJan 11, 2022
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS is…

  • CVE-2020-28679HigJan 10, 2022
    risk 0.57cvss 8.8epss 0.03

    A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request.

  • CVE-2021-25054HigJan 10, 2022
    risk 0.57cvss 8.8epss 0.01

    The WPcalc WordPress plugin through 2.1 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authenticated SQL Injection vulnerability.

  • CVE-2021-25030HigJan 3, 2022
    risk 0.57cvss 8.8epss 0.01

    The Events Made Easy WordPress plugin before 2.2.36 does not sanitise and escape the search_text parameter before using it in a SQL statement via the eme_searchmail AJAX action, available to any authenticated users. As a result, users with a role as low as subscriber can call it…

  • CVE-2021-44161HigDec 29, 2021
    risk 0.57cvss 8.8epss 0.01

    Changing MOTP (Mobile One Time Password) system’s specific function parameter has insufficient validation for user input. A attacker in local area network can perform SQL injection attack to read, modify or delete backend database without authentication.

  • CVE-2021-21936HigDec 22, 2021
    risk 0.57cvss 8.8epss 0.01

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘health_alt_filter’ parameter. This can be done as any authenticated user or through cross-site request forgery.

  • CVE-2021-21917HigDec 22, 2021
    risk 0.57cvss 8.8epss 0.01

    An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at '‘ord’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This can be done…

  • CVE-2021-21916HigDec 22, 2021
    risk 0.57cvss 8.8epss 0.01

    An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at 'description_filter’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This…

  • CVE-2021-21915HigDec 22, 2021
    risk 0.57cvss 8.8epss 0.01

    An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at ‘company_filter’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This…

  • CVE-2021-43630HigDec 22, 2021
    risk 0.57cvss 8.8epss 0.02

    Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in add_patient.php. As a result, an authenticated malicious user can compromise the databases system and in some cases leverage this vulnerability to get remote code execution on…

  • CVE-2021-44874HigDec 21, 2021
    risk 0.57cvss 8.8epss 0.01

    Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to Insecure design on report build via SQL query. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application counterparts.…

  • CVE-2021-24846HigDec 21, 2021
    risk 0.57cvss 8.8epss 0.01

    The get_query() function of the Ni WooCommerce Custom Order Status WordPress plugin before 1.9.7, used by the niwoocos_ajax AJAX action, available to all authenticated users, does not properly sanitise the sort parameter before using it in a SQL statement, leading to an SQL…