VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,812)

page 55 of 1,041
  • CVE-2024-57328CriJan 23, 2025
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability exists in the login form of Online Food Ordering System v1.0. The vulnerability arises because the input fields username and password are not properly sanitized, allowing attackers to inject malicious SQL queries to bypass authentication and gain…

  • CVE-2023-37777CriJan 22, 2025
    risk 0.64cvss 9.8epss 0.00

    A SQL injection vulnerability exists in Synnefo Internet Management Software (IMS) version 2023 and earlier. This vulnerability occurs due to improper input validation in a specific API endpoint parameter allowing an attacker to manipulate SQL queries via crafted input.…

  • CVE-2023-27113CriJan 21, 2025
    risk 0.64cvss 9.8epss 0.01

    pearProjectApi v2.8.10 was discovered to contain a SQL injection vulnerability via the organizationCode parameter at project.php.

  • CVE-2023-27112CriJan 21, 2025
    risk 0.64cvss 9.8epss 0.01

    pearProjectApi v2.8.10 was discovered to contain a SQL injection vulnerability via the projectCode parameter at project.php.

  • CVE-2025-0585CriJan 20, 2025
    risk 0.64cvss 9.8epss 0.01

    The a+HRD from aEnrich Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

  • CVE-2024-57035CriJan 17, 2025
    risk 0.64cvss 9.8epss 0.01

    WeGIA v3.2.0 is vulnerable to SQL Injection viathe nextPage parameter in /controle/control.php.

  • CVE-2024-57034CriJan 17, 2025
    risk 0.64cvss 9.8epss 0.01

    WeGIA < 3.2.0 is vulnerable to SQL Injection in query_geracao_auto.php via the query parameter.

  • CVE-2024-57031CriJan 17, 2025
    risk 0.64cvss 9.8epss 0.01

    WeGIA < 3.2.0 is vulnerable to SQL Injection in /funcionario/remuneracao.php via the id_funcionario parameter.

  • CVE-2024-57768CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.01

    JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRole.key.

  • CVE-2025-0455CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.01

    The airPASS from NetVision Information has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

  • CVE-2024-8855CriJan 7, 2025
    risk 0.64cvss 9.8epss 0.01

    The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing editors and above to perform SQL injection attacks

  • CVE-2024-47926CriDec 30, 2024
    risk 0.64cvss 9.8epss 0.01

    Tecnick TCExam – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

  • CVE-2024-50717CriDec 27, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Smart Agent v.1.1.0 allows a remote attacker to execute arbitrary code via the client parameter in the /recuperaLog.php component.

  • CVE-2024-50716CriDec 27, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Smart Agent v.1.1.0 allows a remote attacker to execute arbitrary code via the id parameter in the /sendPushManually.php component.

  • CVE-2024-50713CriDec 27, 2024
    risk 0.64cvss 9.8epss 0.01

    SmartAgent v1.1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tests/interface.php.

  • CVE-2024-8950CriDec 25, 2024
    risk 0.64cvss 9.9epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arne Informatics Piramit Automation allows Blind SQL Injection. This issue affects Piramit Automation: before 27.09.2024.

  • CVE-2024-55509CriDec 20, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in CodeAstro Complaint Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via the id parameter of the delete.php component.

  • CVE-2024-12727CriDec 19, 2024
    risk 0.64cvss 9.8epss 0.01

    A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the reporting database and can lead to remote code execution if a specific configuration of Secure PDF eXchange (SPX) is enabled in…

  • CVE-2024-10244CriDec 19, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ISDO Software Web Software allows SQL Injection. This issue affects Web Software: before 3.6.

  • CVE-2024-8972CriDec 17, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mobil365 Informatics Saha365 App allows SQL Injection. This issue affects Saha365 App: before 30.09.2024.