VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,856)

page 275 of 1,043
  • CVE-2020-6145HigAug 10, 2020
    risk 0.57cvss 8.8epss 0.02

    An SQL injection vulnerability exists in the frappe.desk.reportview.get functionality of ERPNext 11.1.38. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

  • CVE-2020-15714HigJul 28, 2020
    risk 0.57cvss 8.8epss 0.03

    rConfig 3.9.5 is vulnerable to SQL injection. A remote authenticated attacker could send crafted SQL statements to the devices.crud.php script using the custom_Location parameter, which could allow the attacker to view, add, modify, or delete information in the back-end database.

  • CVE-2020-15713HigJul 28, 2020
    risk 0.57cvss 8.8epss 0.03

    rConfig 3.9.5 is vulnerable to SQL injection. A remote authenticated attacker could send crafted SQL statements to the devices.php script using the sortBy parameter, which could allow the attacker to view, add, modify, or delete information in the back-end database.

  • CVE-2020-15887HigJul 23, 2020
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability in softwareupdate_controller.php in the Software Update module before 1.6 for MunkiReport allows attackers to execute arbitrary SQL commands via the last URL parameter of the /module/softwareupdate/get_tab_data/ endpoint.

  • CVE-2020-15886HigJul 23, 2020
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability in reportdata_controller.php in the reportdata module before 3.5 for MunkiReport allows attackers to execute arbitrary SQL commands via the req parameter of the /module/reportdata/ip endpoint.

  • CVE-2020-15884HigJul 23, 2020
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability in TableQuery.php in MunkiReport before 5.6.3 allows attackers to execute arbitrary SQL commands via the order[0][dir] field on POST requests to /datatables/data.

  • CVE-2020-15072HigJul 8, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in phpList through 3.5.4. An error-based SQL Injection vulnerability exists via the Import Administrators section.

  • CVE-2020-3973HigJul 8, 2020
    risk 0.57cvss 8.8epss 0.01

    The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection. A malicious actor with tenant access to Velocloud Orchestrator could enter specially crafted SQL queries and obtain data to which they are not privileged.

  • CVE-2020-14295HigJun 17, 2020
    risk 0.57cvss 7.2epss 0.86

    A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead to remote command execution because the product accepts stacked queries.

  • CVE-2020-14159HigJun 15, 2020
    risk 0.57cvss 8.8epss 0.02

    By using an Automate API in ConnectWise Automate before 2020.5.178, a remote authenticated user could execute commands and/or modifications within an individual Automate instance by triggering an SQL injection vulnerability in /LabTech/agent.aspx. This affects versions before…

  • CVE-2020-13996HigJun 9, 2020
    risk 0.57cvss 8.8epss 0.01

    The J2Store plugin before 3.3.13 for Joomla! allows a SQL injection attack by a trusted store manager.

  • CVE-2020-6249HigMay 12, 2020
    risk 0.57cvss 8.8epss 0.01

    The use of an admin backend report within SAP Master Data Governance, versions - S4CORE 101, S4FND 102, 103, 104, SAP_BS_FND 748; allows an attacker to execute crafted database queries, exposing the backend database, leading to SQL Injection.

  • CVE-2020-6241HigMay 12, 2020
    risk 0.57cvss 8.8epss 0.01

    SAP Adaptive Server Enterprise, version 16.0, allows an authenticated user to execute crafted database queries to elevate privileges of users in the system, leading to SQL Injection.

  • CVE-2020-12104HigMay 5, 2020
    risk 0.57cvss 8.8epss 0.02

    The Import feature in the wp-advanced-search plugin 3.3.6 for WordPress is vulnerable to authenticated SQL injection via an uploaded .sql file. An attacker can use this to execute SQL commands without any validation.

  • CVE-2020-12461HigApr 29, 2020
    risk 0.57cvss 8.8epss 0.02

    PHP-Fusion 9.03.50 allows SQL Injection because maincore.php has an insufficient protection mechanism. An attacker can develop a crafted payload that can be inserted into the sort_order GET parameter on the members.php members search page. This parameter allows for control over…

  • CVE-2020-10512HigApr 15, 2020
    risk 0.57cvss 8.8epss 0.01

    HGiga C&Cmail CCMAILQ before olln-calendar-6.0-100.i386.rpm and CCMAILN before olln-calendar-5.0-100.i386.rpm contains a SQL Injection vulnerability which allows attackers to injecting SQL commands in the URL parameter to execute unauthorized commands.

  • CVE-2020-5292HigMar 31, 2020
    risk 0.57cvss 8.7epss 0.01

    Leantime before versions 2.0.15 and 2.1-beta3 has a SQL Injection vulnerability. The impact is high. Malicious users/attackers can execute arbitrary SQL queries negatively affecting the confidentiality, integrity, and availability of the site. Attackers can exfiltrate data like…

  • CVE-2019-7755HigMar 30, 2020
    risk 0.57cvss 8.8epss 0.02

    In webERP 4.15, the Import Bank Transactions function fails to sanitize the content of imported MT940 bank statement files, resulting in the execution of arbitrary SQL queries, aka SQL Injection.

  • CVE-2020-10817HigMar 27, 2020
    risk 0.57cvss 8.8epss 0.02

    The custom-searchable-data-entry-system (aka Custom Searchable Data Entry System) plugin through 1.7.1 for WordPress allows SQL Injection. NOTE: this product is discontinued.

  • CVE-2020-9521HigMar 26, 2020
    risk 0.57cvss 8.8epss 0.01

    An SQL injection vulnerability was discovered in Micro Focus Service Manager Automation (SMA), affecting versions 2019.08, 2019.05, 2019.02, 2018.08, 2018.05, 2018.02. The vulnerability could allow for the improper neutralization of special elements in SQL commands and may lead…