VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,856)

page 266 of 1,043
  • CVE-2021-3860HigDec 20, 2021
    risk 0.57cvss 8.8epss 0.01

    JFrog Artifactory before 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection by a low privileged authenticated user due to incomplete validation when performing an SQL query.

  • CVE-2021-45041HigDec 19, 2021
    risk 0.57cvss 8.8epss 0.02

    SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project module, involving resource_id and start_date.

  • CVE-2021-41262HigDec 16, 2021
    risk 0.57cvss 8.8epss 0.01

    Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 are subject to SQL injection attacks by users with "member" privilege. Users are advised to upgrade to version 0.9.6 as soon as possible. There…

  • CVE-2021-43806HigDec 15, 2021
    risk 0.57cvss 8.8epss 0.02

    Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In affected versions Tuleap does not sanitize properly user settings when constructing the SQL query to browse and search commits in the CVS repositories. A authenticated…

  • CVE-2021-41365HigDec 15, 2021
    risk 0.57cvss 8.8epss 0.03

    Microsoft Defender for IoT Remote Code Execution Vulnerability

  • CVE-2021-24848HigDec 13, 2021
    risk 0.57cvss 8.8epss 0.01

    The mediamaticAjaxRenameCategory AJAX action of the Mediamatic WordPress plugin before 2.8.1, available to any authenticated user, does not sanitise the categoryID parameter before using it in a SQL statement, leading to an SQL injection

  • CVE-2021-43608CriDec 9, 2021
    risk 0.57cvss 9.8epss 0.02

    Doctrine DBAL 3.x before 3.1.4 allows SQL Injection. The escaping of offset and length inputs to the generation of a LIMIT clause was not probably cast to an integer, allowing SQL injection to take place if application developers passed unescaped user input to the DBAL…

  • CVE-2021-40282HigDec 9, 2021
    risk 0.57cvss 8.8epss 0.01

    An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, abd 2021 in dl/dl_download.php. when registering ordinary users.

  • CVE-2021-40281HigDec 9, 2021
    risk 0.57cvss 8.8epss 0.01

    An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 in dl/dl_print.php when registering ordinary users.

  • CVE-2021-42760HigDec 8, 2021
    risk 0.57cvss 8.8epss 0.01

    A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to disclose sensitive information from DB tables via crafted requests.

  • CVE-2021-40313HigDec 6, 2021
    risk 0.57cvss 8.8epss 0.01

    Piwigo v11.5 was discovered to contain a SQL injection vulnerability via the parameter pwg_token in /admin/batch_manager_global.php.

  • CVE-2021-36328HigNov 30, 2021
    risk 0.57cvss 8.8epss 0.01

    Dell EMC Streaming Data Platform versions before 1.3 contain a SQL Injection Vulnerability. A remote malicious user may potentially exploit this vulnerability to execute SQL commands to perform unauthorized actions and retrieve sensitive information from the database.

  • CVE-2021-24755HigNov 29, 2021
    risk 0.57cvss 8.8epss 0.01

    The myCred WordPress plugin before 2.3 does not validate or escape the fields parameter before using it in a SQL statement, leading to an SQL injection exploitable by any authenticated user

  • CVE-2021-24748HigNov 29, 2021
    risk 0.57cvss 8.8epss 0.01

    The Email Before Download WordPress plugin before 6.8 does not properly validate and escape the order and orderby GET parameters before using them in SQL statements, leading to authenticated SQL injection issues

  • CVE-2021-36807HigNov 26, 2021
    risk 0.57cvss 8.8epss 0.01

    An authenticated user could potentially execute code via an SQLi vulnerability in the user portal of SG UTM before version 9.708 MR8.

  • CVE-2021-24847HigNov 17, 2021
    risk 0.57cvss 8.8epss 0.01

    The importFromRedirection AJAX action of the SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 8.2, available to any authenticated user, does not properly sanitise the offset parameter before using it in a SQL statement, leading an SQL injection when the…

  • CVE-2021-24772HigNov 17, 2021
    risk 0.57cvss 8.8epss 0.02

    The Stream WordPress plugin before 3.8.2 does not sanitise and validate the order GET parameter from the Stream Records admin dashboard before using it in a SQL statement, leading to an SQL injection issue.

  • CVE-2021-24758HigNov 17, 2021
    risk 0.57cvss 8.8epss 0.01

    The Email Log WordPress plugin before 2.4.7 does not properly validate, sanitise and escape the "orderby" and "order" GET parameters before using them in SQL statement in the admin dashboard, leading to SQL injections

  • CVE-2021-26795HigNov 14, 2021
    risk 0.57cvss 8.8epss 0.02

    A SQL Injection vulnerability in /appliance/shiftmgn.php in TalariaX sendQuick Alert Plus Server Admin 4.3 before 8HF11 allows attackers to obtain sensitive information via a Roster Time to Roster Management.

  • CVE-2021-24835HigNov 8, 2021
    risk 0.57cvss 8.8epss 0.01

    The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible WordPress plugin before 6.5.12, when used in combination with another WCFM - WooCommerce Multivendor plugin such as WCFM - WooCommerce Multivendor Marketplace, does not escape the…