VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,861)

page 533 of 1,044
  • CVE-2024-1793HigMar 13, 2024
    risk 0.47cvss 7.2epss 0.01

    The AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth plugin for WordPress is vulnerable to SQL Injection via the 'post_id' parameter in all versions up to, and including, 7.3.14 due to insufficient escaping on the user…

  • CVE-2024-1068HigMar 11, 2024
    risk 0.47cvss 7.2epss 0.01

    The 404 Solution WordPress plugin before 2.35.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admins.

  • CVE-2024-2264HigMar 7, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in keerti1924 PHP-MYSQL-User-Login-System 1.0. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument email leads to sql injection. The attack may be launched…

  • CVE-2023-49968HigMar 5, 2024
    risk 0.47cvss 7.3epss 0.00

    Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/manage_department.php.

  • CVE-2024-27515HigFeb 28, 2024
    risk 0.47cvss 7.2epss 0.01

    Osclass 5.1.2 is vulnerable to SQL Injection.

  • CVE-2024-24027HigFeb 27, 2024
    risk 0.47cvss 7.2epss 0.01

    SQL Injection vulnerability in Likeshop before 2.5.7 allows attackers to run abitrary SQL commands via the function DistributionMemberLogic::getFansLists.

  • CVE-2024-24323HigFeb 27, 2024
    risk 0.47cvss 7.2epss 0.01

    SQL injection vulnerability in linlinjava litemall v.1.8.0 allows a remote attacker to obtain sensitive information via the nickname, consignee, orderSN, orderStatusArray parameters of the AdminOrdercontroller.java component.

  • CVE-2024-1826HigFeb 23, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in code-projects Library System 1.0 and classified as critical. This vulnerability affects unknown code of the file Source/librarian/user/student/login.php. The manipulation of the argument username/password leads to sql injection. The attack can…

  • CVE-2024-1824HigFeb 23, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in CodeAstro House Rental Management System 1.0. Affected by this issue is some unknown functionality of the file signing.php. The manipulation of the argument uname/password leads to sql injection. The attack may…

  • CVE-2024-1820HigFeb 23, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in code-projects Crime Reporting System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file inchargelogin.php. The manipulation of the argument email/password leads to sql injection. The attack can be initiated…

  • CVE-2024-1776HigFeb 23, 2024
    risk 0.47cvss 7.2epss 0.01

    The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via the 'form-id' parameter in all versions up to, and including, 1.1.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…

  • CVE-2023-52155HigFeb 21, 2024
    risk 0.47cvss 7.2epss 0.01

    A SQL Injection vulnerability in /admin/sauvegarde/run.php in PMB 7.4.7 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via the sauvegardes variable through the /admin/sauvegarde/run.php endpoint.

  • CVE-2024-25213HigFeb 14, 2024
    risk 0.47cvss 7.2epss 0.01

    Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /edit.php.

  • CVE-2024-25212HigFeb 14, 2024
    risk 0.47cvss 7.2epss 0.01

    Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /delete.php.

  • CVE-2024-1197HigFeb 2, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in SourceCodester Testimonial Page Manager 1.0. This issue affects some unknown processing of the file delete-testimonial.php of the component HTTP GET Request Handler. The manipulation of the argument testimony…

  • CVE-2024-24140HigJan 29, 2024
    risk 0.47cvss 7.2epss 0.01

    Sourcecodester Daily Habit Tracker App 1.0 allows SQL Injection via the parameter 'tracker.'

  • CVE-2024-24139HigJan 29, 2024
    risk 0.47cvss 7.2epss 0.01

    Sourcecodester Login System with Email Verification 1.0 allows SQL Injection via the 'user' parameter.

  • CVE-2024-0405HigJan 17, 2024
    risk 0.47cvss 7.2epss 0.01

    The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin, version 1.5.3, is vulnerable to Post-Authenticated SQL Injection via multiple JSON parameters in the /wp-json/burst/v1/data/compare endpoint. Affected parameters include 'browser', 'device', 'page_id',…

  • CVE-2024-22628HigJan 16, 2024
    risk 0.47cvss 7.2epss 0.01

    Budget and Expense Tracker System v1.0 is vulnerable to SQL Injection via /expense_budget/admin/?page=reports/budget&date_start=2023-12-28&date_end=

  • CVE-2024-22627HigJan 16, 2024
    risk 0.47cvss 7.2epss 0.01

    Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_distributor.php?id=.