CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,861)
page 542 of 1,044| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-43228 | Hig | 0.47 | 7.2 | 0.01 | Oct 28, 2022 | Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /clearance/clearance.php. | ||
| CVE-2022-43276 | Hig | 0.47 | 7.2 | 0.01 | Oct 28, 2022 | Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the productId parameter at /php_action/fetchSelectedfood.php. | ||
| CVE-2022-3302 | Hig | 0.47 | 7.2 | 0.01 | Oct 25, 2022 | The Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.185.1 does not validate ids before using them in a SQL statement, which could lead to SQL injection exploitable by high privilege users such as admin | ||
| CVE-2022-3300 | Hig | 0.47 | 7.2 | 0.01 | Oct 25, 2022 | The Form Maker by 10Web WordPress plugin before 1.15.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin | ||
| CVE-2022-42218 | Hig | 0.47 | 7.2 | 0.01 | Oct 18, 2022 | Open Source SACCO Management System v1.0 vulnerable to SQL Injection via /sacco_shield/manage_loan.php. | ||
| CVE-2022-42143 | Hig | 0.47 | 7.2 | 0.01 | Oct 17, 2022 | Open Source SACCO Management System v1.0 is vulnerable to SQL Injection via /sacco_shield/manage_payment.php. | ||
| CVE-2022-41498 | Hig | 0.47 | 7.2 | 0.01 | Oct 17, 2022 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editbrand.php. | ||
| CVE-2022-3243 | Hig | 0.47 | 7.2 | 0.01 | Oct 17, 2022 | The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin | ||
| CVE-2022-3131 | Hig | 0.47 | 7.2 | 0.01 | Oct 17, 2022 | The Search Logger WordPress plugin through 0.9 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users | ||
| CVE-2022-41416 | Hig | 0.47 | 7.2 | 0.01 | Oct 14, 2022 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /user/update_booking.php. | ||
| CVE-2022-42232 | Hig | 0.47 | 7.2 | 0.01 | Oct 14, 2022 | Simple Cold Storage Management System v1.0 is vulnerable to SQL Injection via /csms/classes/Master.php?f=delete_storage. | ||
| CVE-2022-41536 | Hig | 0.47 | 7.2 | 0.01 | Oct 14, 2022 | Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/manage_user.php. | ||
| CVE-2022-41535 | Hig | 0.47 | 7.2 | 0.01 | Oct 14, 2022 | Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/manage_borrower.php. | ||
| CVE-2022-34022 | Hig | 0.47 | 7.2 | 0.01 | Oct 13, 2022 | SQL injection vulnerability in ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 via a crafted POST request to /ResiotQueryDBActive. | ||
| CVE-2022-41532 | Hig | 0.47 | 7.2 | 0.01 | Oct 12, 2022 | Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/ajax.php?action=delete_plan. | ||
| CVE-2022-41530 | Hig | 0.47 | 7.2 | 0.01 | Oct 12, 2022 | Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/ajax.php?action=delete_borrower. | ||
| CVE-2022-41407 | Hig | 0.47 | 7.2 | 0.01 | Oct 12, 2022 | Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=orders/view_order. | ||
| CVE-2022-42230 | Hig | 0.47 | 7.2 | 0.01 | Oct 11, 2022 | Simple Cold Storage Management System v1.0 is vulnerable to SQL Injection via /csms/admin/?page=user/manage_user&id=. | ||
| CVE-2022-42074 | Hig | 0.47 | 7.2 | 0.01 | Oct 7, 2022 | Online Diagnostic Lab Management System v1.0 is vulnerable to SQL Injection via /diagnostic/editcategory.php?id=. | ||
| CVE-2022-42073 | Hig | 0.47 | 7.2 | 0.01 | Oct 7, 2022 | Online Diagnostic Lab Management System v1.0 is vulnerable to SQL Injection via /diagnostic/editclient.php?id=. |
- risk 0.47cvss 7.2epss 0.01
Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /clearance/clearance.php.
- risk 0.47cvss 7.2epss 0.01
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the productId parameter at /php_action/fetchSelectedfood.php.
- risk 0.47cvss 7.2epss 0.01
The Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.185.1 does not validate ids before using them in a SQL statement, which could lead to SQL injection exploitable by high privilege users such as admin
- risk 0.47cvss 7.2epss 0.01
The Form Maker by 10Web WordPress plugin before 1.15.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
- risk 0.47cvss 7.2epss 0.01
Open Source SACCO Management System v1.0 vulnerable to SQL Injection via /sacco_shield/manage_loan.php.
- risk 0.47cvss 7.2epss 0.01
Open Source SACCO Management System v1.0 is vulnerable to SQL Injection via /sacco_shield/manage_payment.php.
- risk 0.47cvss 7.2epss 0.01
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editbrand.php.
- risk 0.47cvss 7.2epss 0.01
The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin
- risk 0.47cvss 7.2epss 0.01
The Search Logger WordPress plugin through 0.9 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users
- risk 0.47cvss 7.2epss 0.01
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /user/update_booking.php.
- risk 0.47cvss 7.2epss 0.01
Simple Cold Storage Management System v1.0 is vulnerable to SQL Injection via /csms/classes/Master.php?f=delete_storage.
- risk 0.47cvss 7.2epss 0.01
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/manage_user.php.
- risk 0.47cvss 7.2epss 0.01
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/manage_borrower.php.
- risk 0.47cvss 7.2epss 0.01
SQL injection vulnerability in ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 via a crafted POST request to /ResiotQueryDBActive.
- risk 0.47cvss 7.2epss 0.01
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/ajax.php?action=delete_plan.
- risk 0.47cvss 7.2epss 0.01
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/ajax.php?action=delete_borrower.
- risk 0.47cvss 7.2epss 0.01
Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=orders/view_order.
- risk 0.47cvss 7.2epss 0.01
Simple Cold Storage Management System v1.0 is vulnerable to SQL Injection via /csms/admin/?page=user/manage_user&id=.
- risk 0.47cvss 7.2epss 0.01
Online Diagnostic Lab Management System v1.0 is vulnerable to SQL Injection via /diagnostic/editcategory.php?id=.
- risk 0.47cvss 7.2epss 0.01
Online Diagnostic Lab Management System v1.0 is vulnerable to SQL Injection via /diagnostic/editclient.php?id=.