VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,861)

page 537 of 1,044
  • CVE-2023-1357HigMar 12, 2023
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in SourceCodester Simple Bakery Shop Management System 1.0. Affected by this issue is some unknown functionality of the component Admin Login. The manipulation of the argument username/password with the input…

  • CVE-2023-25223HigMar 7, 2023
    risk 0.47cvss 7.2epss 0.01

    CRMEB <=1.3.4 is vulnerable to SQL Injection via /api/admin/user/list.

  • CVE-2023-25432HigFeb 28, 2023
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in Online Reviewer Management System v1.0. There is a SQL injection that can directly issue instructions to the background database system via reviewer_0/admins/assessments/course/course-update.php.

  • CVE-2023-0487HigFeb 27, 2023
    risk 0.47cvss 7.2epss 0.01

    The My Sticky Elements WordPress plugin before 2.0.9 does not properly sanitise and escape a parameter before using it in a SQL statement when deleting messages, leading to a SQL injection exploitable by high privilege users such as admin

  • CVE-2023-0895HigFeb 17, 2023
    risk 0.47cvss 7.2epss 0.01

    The WP Coder – add custom html, css and js code plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in versions up to, and including, 2.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…

  • CVE-2023-23007HigFeb 17, 2023
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in ESPCMS P8.21120101 after logging in to the background, there is a SQL injection vulnerability in the function node where members are added.

  • CVE-2022-38868HigFeb 15, 2023
    risk 0.47cvss 7.2epss 0.01

    SQL Injection vulnerability in Ehoney version 2.0.0 in models/protocol.go and models/images.go, allows attackers to execute arbitrary code.

  • CVE-2022-4546HigFeb 13, 2023
    risk 0.47cvss 7.2epss 0.01

    The Mapwiz WordPress plugin through 1.0.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

  • CVE-2023-0774HigFeb 10, 2023
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in SourceCodester Medical Certificate Generator App 1.0 and classified as critical. This vulnerability affects unknown code of the file action.php. The manipulation of the argument lastname leads to sql injection. The attack can be initiated…

  • CVE-2023-24685HigFeb 9, 2023
    risk 0.47cvss 7.2epss 0.01

    ChurchCRM v4.5.3 and below was discovered to contain a SQL injection vulnerability via the Event parameter under the Event Attendance reports module.

  • CVE-2023-24684HigFeb 9, 2023
    risk 0.47cvss 7.2epss 0.01

    ChurchCRM v4.5.3 and below was discovered to contain a SQL injection vulnerability via the EID parameter at GetText.php.

  • CVE-2022-45589HigFeb 6, 2023
    risk 0.47cvss 7.2epss 0.01

    All versions before 8.0.1-R2022-10-RT and 7.3.1-R2022-09-RT of the Talend ESB Runtime are potentially vulnerable to SQL Injection attacks in the provisioning service only. Users of the provisioning service should upgrade to either 8.0.1-R2022-10-RT or 7.3.1-R2022-09-RT or a…

  • CVE-2022-4547HigJan 16, 2023
    risk 0.47cvss 7.2epss 0.01

    The Conditional Payment Methods for WooCommerce WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by [high privilege users such as admin|users with a role as low as admin.

  • CVE-2022-46956HigJan 13, 2023
    risk 0.47cvss 7.2epss 0.01

    Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/manage_user.php.

  • CVE-2022-46953HigJan 13, 2023
    risk 0.47cvss 7.2epss 0.01

    Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/ajax.php?action=save_window.

  • CVE-2022-46952HigJan 13, 2023
    risk 0.47cvss 7.2epss 0.01

    Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/ajax.php?action=delete_user.

  • CVE-2022-46951HigJan 13, 2023
    risk 0.47cvss 7.2epss 0.01

    Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/ajax.php?action=delete_uploads.

  • CVE-2022-46950HigJan 13, 2023
    risk 0.47cvss 7.2epss 0.01

    Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/ajax.php?action=delete_window.

  • CVE-2022-46949HigJan 13, 2023
    risk 0.47cvss 7.2epss 0.01

    Helmet Store Showroom Site v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_helmet.

  • CVE-2022-46947HigJan 13, 2023
    risk 0.47cvss 7.2epss 0.01

    Helmet Store Showroom Site v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_category.