VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,858)

page 339 of 1,043
  • CVE-2023-29245HigSep 19, 2023
    risk 0.53cvss 8.1epss 0.01

    A SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain fields used in the Asset Intelligence functionality of our IDS, may allow an unauthenticated attacker to execute arbitrary SQL statements on the DBMS used by the web…

  • CVE-2023-20211HigAug 16, 2023
    risk 0.53cvss 8.1epss 0.01

    A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct SQL injection attacks on an…

  • CVE-2023-34418HigJun 26, 2023
    risk 0.53cvss 8.1epss 0.01

    A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LXCA due to a SQL injection vulnerability in a specific web API.

  • CVE-2022-47586HigJun 19, 2023
    risk 0.53cvss 8.2epss 0.01

    Unauth. SQL Injection (SQLi) vulnerability in Themefic Ultimate Addons for Contact Form 7 plugin <= 3.1.23 versions.

  • CVE-2022-45355HigMar 29, 2023
    risk 0.53cvss 8.2epss 0.01

    Auth. (admin+) SQL Injection (SQLi) vulnerability in ThimPress WP Pipes plugin <= 1.33 versions.

  • CVE-2022-45786HigFeb 4, 2023
    risk 0.53cvss 8.1epss 0.01

    There are issues with the AGE drivers for Golang and Python that enable SQL injections to occur. This impacts AGE for PostgreSQL 11 & AGE for PostgreSQL 12, all versions up-to-and-including 1.1.0, when using those drivers. The fix is to update to the latest Golang and Python…

  • CVE-2022-46965HigFeb 2, 2023
    risk 0.53cvss 8.1epss 0.01

    PrestaShop module, totadministrativemandate before v1.7.1 was discovered to contain a SQL injection vulnerability.

  • CVE-2022-4230HigJan 23, 2023
    risk 0.53cvss 8.8epss 0.36

    The WP Statistics WordPress plugin before 13.2.9 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the manage_options capability (admin+), however the plugin has a…

  • CVE-2023-20010HigJan 20, 2023
    risk 0.53cvss 8.1epss 0.01

    A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct SQL injection attacks on an…

  • CVE-2022-46093HigJan 13, 2023
    risk 0.53cvss 8.2epss 0.01

    Hospital Management System v1.0 is vulnerable to SQL Injection. Attackers can gain administrator privileges without the need for a password.

  • CVE-2023-22491HigJan 13, 2023
    risk 0.53cvss 8.1epss 0.01

    Gatsby is a free and open source framework based on React that helps developers build websites and apps. The gatsby-transformer-remark plugin prior to versions 5.25.1 and 6.3.2 passes input through to the `gray-matter` npm package, which is vulnerable to JavaScript injection in…

  • CVE-2022-39303HigOct 13, 2022
    risk 0.53cvss 8.1epss 0.01

    Ree6 is a moderation bot. This vulnerability allows manipulation of SQL queries. This issue has been patched in version 1.7.0 by using Javas PreparedStatements, which allow object setting without the risk of SQL injection. There are currently no known workarounds.

  • CVE-2021-43766HigAug 25, 2022
    risk 0.53cvss 8.1epss 0.01

    Odyssey passes to server unencrypted bytes from man-in-the-middle When Odyssey is configured to use certificate Common Name for client authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL…

  • CVE-2022-2142HigJul 22, 2022
    risk 0.53cvss 8.1epss 0.01

    The affected product is vulnerable to a SQL injection with high attack complexity, which may allow an unauthorized attacker to disclose information.

  • CVE-2022-24690HigJul 18, 2022
    risk 0.53cvss 8.2epss 0.01

    An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. A PresAbs.php SQL Injection vulnerability allows unauthenticated users to taint database data and extract sensitive information via crafted HTTP requests. The type of SQL Injection is blind boolean based. (An…

  • CVE-2022-26348HigJul 6, 2022
    risk 0.53cvss 8.2epss 0.00

    Command Centre Server is vulnerable to SQL Injection via Windows Registry settings for date fields on the server. The Windows Registry setting allows an attacker using the Visitor Management Kiosk, an application designed for public use, to invoke an arbitrary SQL query that has…

  • CVE-2022-29250HigJun 9, 2022
    risk 0.53cvss 8.1epss 0.01

    GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to version 10.0.1 it is possible to add extra information by SQL injection on search pages. In order to exploit this…

  • CVE-2022-29305HigMay 24, 2022
    risk 0.53cvss 8.1epss 0.01

    imgurl v2.31 was discovered to contain a Blind SQL injection vulnerability via /upload/localhost.

  • CVE-2022-24844HigApr 13, 2022
    risk 0.53cvss 8.1epss 0.01

    Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. The problem occurs in the following code in server/service/system/sys_auto_code_pgsql.go, which means that PostgreSQL must be used as the database for this…

  • CVE-2021-23214HigMar 4, 2022
    risk 0.53cvss 8.1epss 0.02

    When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and…