VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,858)

page 318 of 1,043
  • CVE-2023-49335HigMay 20, 2024
    risk 0.54cvss 8.3epss 0.03

    Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while getting file server details.

  • CVE-2023-49334HigMay 20, 2024
    risk 0.54cvss 8.3epss 0.03

    Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while exporting a full summary report.

  • CVE-2023-49333HigMay 20, 2024
    risk 0.54cvss 8.3epss 0.03

    Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the dashboard graph feature.

  • CVE-2023-49332HigMay 20, 2024
    risk 0.54cvss 8.3epss 0.03

    Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while adding file shares.

  • CVE-2023-49331HigMay 20, 2024
    risk 0.54cvss 8.3epss 0.03

    Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the aggregate reports search option.

  • CVE-2023-49330HigMay 20, 2024
    risk 0.54cvss 8.3epss 0.02

    Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while getting aggregate report data.

  • CVE-2024-33404HigMay 6, 2024
    risk 0.54cvss 8.3epss 0.01

    A SQL injection vulnerability in /model/add_student_first_payment.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the index parameter.

  • CVE-2024-23539HigMar 29, 2024
    risk 0.54cvss 8.3epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to version 1.8.5 or 1.9.0, which fix the issue.

  • CVE-2024-24100HigFeb 27, 2024
    risk 0.54cvss 8.3epss 0.01

    Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via PublisherID.

  • CVE-2024-21775HigFeb 16, 2024
    risk 0.54cvss 8.3epss 0.05

    Zoho ManageEngine Exchange Reporter Plus versions 5714 and below are vulnerable to the Authenticated SQL injection in report exporting feature.

  • CVE-2024-0269HigFeb 2, 2024
    risk 0.54cvss 8.3epss 0.05

    ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in File-Summary DrillDown. This issue has been fixed and released in version 7271.

  • CVE-2024-0253HigFeb 2, 2024
    risk 0.54cvss 8.3epss 0.05

    ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in home Graph-Data.

  • CVE-2024-22406CriJan 16, 2024
    risk 0.54cvss 9.3epss 0.01

    Shopware is an open headless commerce platform. The Shopware application API contains a search functionality which enables users to search through information stored within their Shopware instance. The searches performed by this function can be aggregated using the parameters in…

  • CVE-2023-46022HigNov 14, 2023
    risk 0.54cvss 7.8epss 0.01

    SQL Injection vulnerability in delete.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via the 'bid' parameter.

  • CVE-2023-36677HigNov 3, 2023
    risk 0.54cvss 8.3epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager allows SQL Injection.This issue affects SP Project & Document Manager: from n/a through 4.67.

  • CVE-2023-24000HigOct 31, 2023
    risk 0.54cvss 8.2epss 0.03

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GamiPress gamipress allows SQL Injection.This issue affects GamiPress: from n/a through 2.5.7.

  • CVE-2022-42923HigOct 31, 2022
    risk 0.54cvss 8.3epss 0.01

    Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vulnerability could allow an authenticated attacker (with the role of student) to perform a SQL injection on the 'id' parameter in the…

  • CVE-2022-35942CriAug 12, 2022
    risk 0.54cvss 9.3epss 0.01

    Improper input validation on the `contains` LoopBack filter may allow for arbitrary SQL injection. When the extended filter property `contains` is permitted to be interpreted by the Postgres connector, it is possible to inject arbitrary SQL which may affect the confidentiality…

  • CVE-2022-27613HigJul 28, 2022
    risk 0.54cvss 8.3epss 0.01

    Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in webapi component in Synology CardDAV Server before 6.0.10-0153 allows remote authenticated users to inject SQL commands via unspecified vectors.

  • CVE-2021-37589HigJun 7, 2022
    risk 0.54cvss 7.5epss 0.33

    Virtua Cobranca before 12R allows SQL Injection on the login page.