VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,861)

page 534 of 1,044
  • CVE-2024-22626HigJan 16, 2024
    risk 0.47cvss 7.2epss 0.01

    Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_retailer.php?id=.

  • CVE-2024-22625HigJan 16, 2024
    risk 0.47cvss 7.2epss 0.01

    Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_category.php?id=.

  • CVE-2023-2655HigJan 16, 2024
    risk 0.47cvss 7.2epss 0.01

    The Contact Form by WD WordPress plugin through 1.13.23 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

  • CVE-2022-3764HigJan 16, 2024
    risk 0.47cvss 7.2epss 0.01

    The plugin does not filter the "delete_entries" parameter from user requests, leading to an SQL Injection vulnerability.

  • CVE-2021-24151HigJan 16, 2024
    risk 0.47cvss 7.2epss 0.01

    The WP Editor WordPress plugin before 1.2.7 did not sanitise or validate its setting fields leading to an authenticated (admin+) blind SQL injection issue via an arbitrary parameter when making a request to save the settings.

  • CVE-2024-0479HigJan 13, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in Taokeyun up to 1.0.5. It has been classified as critical. Affected is the function login of the file application/index/controller/m/User.php of the component HTTP POST Request Handler. The manipulation of the argument username leads to sql injection.…

  • CVE-2024-0474HigJan 12, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical was found in code-projects Dormitory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file login.php. The manipulation of the argument username leads to sql injection. The attack can be launched…

  • CVE-2023-50162HigJan 9, 2024
    risk 0.47cvss 7.2epss 0.01

    SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and obtain sensitive information via the DoExecSql function.

  • CVE-2024-0182HigJan 1, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Engineers Online Portal 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/ of the component Admin Login. The manipulation of the argument username/password leads to sql injection.…

  • CVE-2023-41623HigDec 12, 2023
    risk 0.47cvss 7.2epss 0.01

    Emlog version pro2.1.14 was discovered to contain a SQL injection vulnerability via the uid parameter at /admin/media.php.

  • CVE-2023-5108HigDec 4, 2023
    risk 0.47cvss 7.2epss 0.01

    The Easy Newsletter Signups WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

  • CVE-2023-46956HigNov 30, 2023
    risk 0.47cvss 7.2epss 0.01

    SQL injection vulnerability in Packers and Movers Management System v.1.0 allows a remote attacker to execute arbitrary code via crafted payload to the /mpms/admin/?page=user/manage_user&id file.

  • CVE-2023-2841HigNov 22, 2023
    risk 0.47cvss 7.2epss 0.01

    The Advanced Local Pickup for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in versions up to, and including, 1.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…

  • CVE-2023-5082HigNov 6, 2023
    risk 0.47cvss 7.2epss 0.01

    The History Log by click5 WordPress plugin before 1.0.13 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when using the Smash Balloon Social Photo Feed plugin alongside it.

  • CVE-2023-43507HigOct 25, 2023
    risk 0.47cvss 7.2epss 0.01

    A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit this vulnerability to obtain and modify…

  • CVE-2023-44047HigSep 27, 2023
    risk 0.47cvss 7.2epss 0.01

    Sourcecodester Toll Tax Management System v1 is vulnerable to SQL Injection.

  • CVE-2023-44044HigSep 27, 2023
    risk 0.47cvss 7.2epss 0.01

    Super Store Finder v3.6 and below was discovered to contain a SQL injection vulnerability via the Search parameter at /admin/stores.php.

  • CVE-2023-5151MedSep 25, 2023
    risk 0.47cvss 6.3epss 0.81

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in D-Link DAR-8000 up to 20151231. Affected by this vulnerability is an unknown functionality of the file /autheditpwd.php. The manipulation of the argument hid_id leads to sql injection. The attack…

  • CVE-2023-40043HigSep 20, 2023
    risk 0.47cvss 7.2epss 0.01

    In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified in the MOVEit Transfer web interface that could allow a MOVEit system administrator account to…

  • CVE-2023-40934HigSep 19, 2023
    risk 0.47cvss 7.2epss 0.02

    A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage host escalations in the Core Configuration Manager to execute arbitrary SQL commands via the host escalation notification settings.