VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,858)

page 337 of 1,043
  • CVE-2024-29828HigMay 31, 2024
    risk 0.53cvss 8.0epss 0.08

    An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.

  • CVE-2024-33402HigMay 28, 2024
    risk 0.53cvss 8.1epss 0.00

    A SQL injection vulnerability in /model/approve_petty_cash.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the id parameter.

  • CVE-2024-36428HigMay 27, 2024
    risk 0.53cvss 8.1epss 0.02

    OrangeHRM 3.3.3 allows admin/viewProjects sortOrder SQL injection.

  • CVE-2024-35090HigMay 23, 2024
    risk 0.53cvss 8.2epss 0.00

    J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysUreportFileMapper.xml.

  • CVE-2024-34949HigMay 20, 2024
    risk 0.53cvss 8.2epss 0.00

    SQL injection vulnerability in Likeshop before 2.5.7 allows attackers to run abitrary SQL commands via the function OrderLogic::getOrderList function, exploited at the /admin/order/lists.html endpoint.

  • CVE-2024-25526HigMay 8, 2024
    risk 0.53cvss 8.1epss 0.01

    RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the project_id parameter at /ProjectManage/pm_gatt_inc.aspx.

  • CVE-2024-25512HigMay 7, 2024
    risk 0.53cvss 8.1epss 0.01

    RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the attach_id parameter at /Bulletin/AttachDownLoad.aspx.

  • CVE-2024-33149HigMay 7, 2024
    risk 0.53cvss 8.1epss 0.00

    J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the myProcessList function.

  • CVE-2024-33410HigMay 6, 2024
    risk 0.53cvss 8.1epss 0.01

    SQL injection vulnerability in /model/delete_range_grade.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the id parameter.

  • CVE-2024-33787HigMay 3, 2024
    risk 0.53cvss 8.2epss 0.00

    Hengan Weighing Management Information Query Platform 2019-2021 53.25 was discovered to contain a SQL injection vulnerability via the tuser_Number parameter at search_user.aspx.

  • CVE-2024-33292HigMay 1, 2024
    risk 0.53cvss 8.2epss 0.00

    SQL Injection vulnerability in Realisation MGSD v.1.0 allows a remote attacker to obtain sensitive information via the id parameter.

  • CVE-2024-32212HigMay 1, 2024
    risk 0.53cvss 8.1epss 0.01

    SQL Injection vulnerability in LOGINT LoMag Inventory Management v1.0.20.120 and before allows an attacker to execute arbitrary code via the ArticleGetGroups, DocAddDocument, ClassClickShop and frmSettings components.

  • CVE-2024-29320HigApr 30, 2024
    risk 0.53cvss 8.1epss 0.01

    Wallos before 1.15.3 is vulnerable to SQL Injection via the category and payment parameters to /subscriptions/get.php.

  • CVE-2024-4309HigApr 29, 2024
    risk 0.53cvss 8.1epss 0.00

    SQL injection vulnerability in HubBank affecting version 1.0.2. This vulnerability could allow an attacker to send a specially crafted SQL query to the database through different endpoints (/user/transaction.php?id=1, /user/credit-debit_transaction.php?id=1,/user/view_transaction…

  • CVE-2024-4308HigApr 29, 2024
    risk 0.53cvss 8.1epss 0.00

    SQL injection vulnerability in HubBank affecting version 1.0.2. This vulnerability could allow an attacker to send a specially crafted SQL query to the database through different endpoints (/admin/view_users.php?id=1,/admin/viewloan-trans.php?id=1,/admin/view-deposit.php?id=1,/ad…

  • CVE-2024-4307HigApr 29, 2024
    risk 0.53cvss 8.1epss 0.00

    SQL injection vulnerability in HubBank affecting version 1.0.2. This vulnerability could allow an attacker to send a specially crafted SQL query to the database through different endpoints (/accounts/activities.php?id=1, /accounts/view-deposit.php?id=1, /accounts/view_cards.…

  • CVE-2024-30928HigApr 18, 2024
    risk 0.53cvss 8.1epss 0.01

    SQL Injection vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary SQL commands via 'classids' Parameter in ajax/query.slide.next.inc

  • CVE-2024-22719HigApr 11, 2024
    risk 0.53cvss 8.1epss 0.01

    SQL Injection vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary SQL commands via the 'keyword' when searching for a client.

  • CVE-2024-2592HigMar 18, 2024
    risk 0.53cvss 8.2epss 0.00

    Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/modules/person/pic_show.php, in the 'person_id' parameter. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information…

  • CVE-2024-2591HigMar 18, 2024
    risk 0.53cvss 8.2epss 0.01

    Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/modules/book/main/bookdetail_group.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information…