CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,861)
page 544 of 1,044| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-40927 | Hig | 0.47 | 7.2 | 0.01 | Sep 26, 2022 | Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_designation. | ||
| CVE-2022-40926 | Hig | 0.47 | 7.2 | 0.01 | Sep 26, 2022 | Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_leave_type. | ||
| CVE-2022-40403 | Hig | 0.47 | 7.2 | 0.01 | Sep 26, 2022 | Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/feature_edit.php. | ||
| CVE-2022-40093 | Hig | 0.47 | 7.2 | 0.01 | Sep 23, 2022 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_tax.php. | ||
| CVE-2022-40092 | Hig | 0.47 | 7.2 | 0.01 | Sep 23, 2022 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_payment.php. | ||
| CVE-2022-40091 | Hig | 0.47 | 7.2 | 0.01 | Sep 23, 2022 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_packages.php. | ||
| CVE-2022-40935 | Hig | 0.47 | 7.2 | 0.01 | Sep 22, 2022 | Online Pet Shop We App v1.0 is vulnerable to SQL Injection via /pet_shop/classes/Master.php?f=delete_category,id. | ||
| CVE-2022-40934 | Hig | 0.47 | 7.2 | 0.01 | Sep 22, 2022 | Online Pet Shop We App v1.0 is vulnerable to SQL injection via /pet_shop/classes/Master.php?f=delete_sub_category,id | ||
| CVE-2022-40933 | Hig | 0.47 | 7.2 | 0.01 | Sep 22, 2022 | Online Pet Shop We App v1.0 by oretnom23 is vulnerable to SQL injection via /pet_shop/classes/Master.php?f=delete_order,id. | ||
| CVE-2022-40447 | Hig | 0.47 | 7.2 | 0.01 | Sep 22, 2022 | ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the keyword parameter at /admin/baojia_list.php. | ||
| CVE-2022-40446 | Hig | 0.47 | 7.2 | 0.01 | Sep 22, 2022 | ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the component /admin/sendmailto.php?tomail=&groupid=. | ||
| CVE-2022-40026 | Hig | 0.47 | 7.2 | 0.01 | Sep 21, 2022 | SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at board.php. | ||
| CVE-2022-38576 | Hig | 0.47 | 7.2 | 0.01 | Sep 19, 2022 | Interview Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /interview/delete.php?action=deletecand&id=. | ||
| CVE-2022-38878 | Hig | 0.47 | 7.2 | 0.01 | Sep 16, 2022 | School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/event/index.php?view=edit&id=. | ||
| CVE-2022-35193 | Hig | 0.47 | 7.2 | 0.01 | Sep 16, 2022 | TestLink v1.9.20 was discovered to contain a SQL injection vulnerability via /lib/execute/execNavigator.php. | ||
| CVE-2022-38833 | Hig | 0.47 | 7.2 | 0.01 | Sep 16, 2022 | School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/modstudent/index.php?view=view&id=. | ||
| CVE-2022-38832 | Hig | 0.47 | 7.2 | 0.01 | Sep 16, 2022 | School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/department/index.php?view=edit&id=. | ||
| CVE-2022-38595 | Hig | 0.47 | 7.2 | 0.01 | Sep 15, 2022 | Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_user.php. | ||
| CVE-2022-38594 | Hig | 0.47 | 7.2 | 0.01 | Sep 15, 2022 | Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_visitor.php. | ||
| CVE-2022-38304 | Hig | 0.47 | 7.2 | 0.01 | Sep 12, 2022 | Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /maintenance/manage_leave_type.php. |
- risk 0.47cvss 7.2epss 0.01
Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_designation.
- risk 0.47cvss 7.2epss 0.01
Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_leave_type.
- risk 0.47cvss 7.2epss 0.01
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/feature_edit.php.
- risk 0.47cvss 7.2epss 0.01
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_tax.php.
- risk 0.47cvss 7.2epss 0.01
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_payment.php.
- risk 0.47cvss 7.2epss 0.01
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_packages.php.
- risk 0.47cvss 7.2epss 0.01
Online Pet Shop We App v1.0 is vulnerable to SQL Injection via /pet_shop/classes/Master.php?f=delete_category,id.
- risk 0.47cvss 7.2epss 0.01
Online Pet Shop We App v1.0 is vulnerable to SQL injection via /pet_shop/classes/Master.php?f=delete_sub_category,id
- risk 0.47cvss 7.2epss 0.01
Online Pet Shop We App v1.0 by oretnom23 is vulnerable to SQL injection via /pet_shop/classes/Master.php?f=delete_order,id.
- risk 0.47cvss 7.2epss 0.01
ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the keyword parameter at /admin/baojia_list.php.
- risk 0.47cvss 7.2epss 0.01
ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the component /admin/sendmailto.php?tomail=&groupid=.
- risk 0.47cvss 7.2epss 0.01
SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at board.php.
- risk 0.47cvss 7.2epss 0.01
Interview Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /interview/delete.php?action=deletecand&id=.
- risk 0.47cvss 7.2epss 0.01
School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/event/index.php?view=edit&id=.
- risk 0.47cvss 7.2epss 0.01
TestLink v1.9.20 was discovered to contain a SQL injection vulnerability via /lib/execute/execNavigator.php.
- risk 0.47cvss 7.2epss 0.01
School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/modstudent/index.php?view=view&id=.
- risk 0.47cvss 7.2epss 0.01
School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/department/index.php?view=edit&id=.
- risk 0.47cvss 7.2epss 0.01
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_user.php.
- risk 0.47cvss 7.2epss 0.01
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_visitor.php.
- risk 0.47cvss 7.2epss 0.01
Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /maintenance/manage_leave_type.php.