VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,861)

page 531 of 1,044
  • CVE-2024-42994HigAug 16, 2024
    risk 0.47cvss 7.2epss 0.00

    VTiger CRM <= 8.1.0 does not properly sanitize user input before using it in a SQL statement, leading to a SQL Injection in the "CompanyDetails" operation of the "MailManager" module.

  • CVE-2024-7839HigAug 15, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in itsourcecode Billing System 1.0. This affects an unknown part of the file addbill.php. The manipulation of the argument owners_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2024-7838HigAug 15, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in itsourcecode Online Food Ordering System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /addcategory.php. The manipulation of the argument cname leads to sql injection. The attack may be launched…

  • CVE-2024-7461HigAug 5, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in ForIP Tecnologia Administração PABX 1.x. It has been rated as critical. Affected by this issue is some unknown functionality of the file /authMonitCallcenter of the component monitcallcenter. The manipulation of the argument user leads to sql…

  • CVE-2024-41915HigJul 30, 2024
    risk 0.47cvss 7.2epss 0.01

    A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit this vulnerability to obtain and modify…

  • CVE-2024-7196HigJul 29, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Complaints Report Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login. The manipulation of the argument username leads to sql…

  • CVE-2024-7101HigJul 25, 2024
    risk 0.47cvss 7.3epss 0.00

    A vulnerability, which was classified as critical, has been found in ForIP Tecnologia Administração PABX 1.x. This issue affects some unknown processing of the file /login of the component Authentication Form. The manipulation of the argument usuario leads to sql injection.…

  • CVE-2024-41550HigJul 24, 2024
    risk 0.47cvss 7.2epss 0.00

    CampCodes Supplier Management System v1.0 is vulnerable to SQL injection via Supply_Management_System/admin/view_invoice_items.php?id= .

  • CVE-2024-6898HigJul 19, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Record Management System 1.0. It has been classified as critical. This affects an unknown part of the file index.php. The manipulation of the argument UserName leads to sql injection. It is possible to initiate the attack remotely. The…

  • CVE-2024-40560HigJul 15, 2024
    risk 0.47cvss 7.3epss 0.00

    Tmall_demo before v2024.07.03 was discovered to contain a SQL injection vulnerability.

  • CVE-2024-6418HigJun 30, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Medicine Tracker System 1.0. This affects an unknown part of the file /classes/Users.php?f=register_user. The manipulation of the argument username leads to sql injection. It is possible to initiate the…

  • CVE-2024-6268HigJun 23, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in lahirudanushka School Management System 1.0.0/1.0.1. Affected by this issue is some unknown functionality of the file login.php of the component Login Page. The manipulation of the argument email leads to sql…

  • CVE-2024-29390HigJun 20, 2024
    risk 0.47cvss 7.3epss 0.00

    Daily Expenses Management System version 1.0, developed by PHP Gurukul, contains a time-based blind SQL injection vulnerability in the 'add-expense.php' page. An attacker can exploit the 'item' parameter in a POST request to execute arbitrary SQL commands in the backend…

  • CVE-2024-6196HigJun 20, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in itsourcecode Banking Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin_class.php. The manipulation of the argument username leads to sql injection. The attack may be launched…

  • CVE-2024-6193HigJun 20, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in itsourcecode Vehicle Management System 1.0. This issue affects some unknown processing of the file driverprofile.php. The manipulation of the argument driverid leads to sql injection. The attack may be…

  • CVE-2024-6192HigJun 20, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical was found in itsourcecode Loan Management System 1.0. This vulnerability affects unknown code of the file login.php of the component Login Page. The manipulation of the argument username leads to sql injection. The attack can be initiated…

  • CVE-2024-6191HigJun 20, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in itsourcecode Student Management System 1.0. This affects an unknown part of the file login.php of the component Login Page. The manipulation of the argument user leads to sql injection. It is possible to initiate the…

  • CVE-2024-6042HigJun 17, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in itsourcecode Real Estate Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file property-detail.php. The manipulation of the argument id leads to sql injection. The attack may be…

  • CVE-2024-6003HigJun 14, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in Guangdong Baolun Electronics IP Network Broadcasting Service Platform 2.0. It has been classified as critical. Affected is an unknown function of the file /api/v2/maps. The manipulation of the argument orderColumn leads to sql injection. It is…

  • CVE-2024-4145HigJun 13, 2024
    risk 0.47cvss 7.2epss 0.00

    The Search & Replace WordPress plugin before 3.2.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks (such as within a multi-site network).