VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,812)

page 57 of 1,041
  • CVE-2024-41579CriDec 5, 2024
    risk 0.64cvss 9.8epss 0.01

    DTStack Taier 1.4.0 allows remote attackers to specify the jobName parameter in the console listNames function to cause a SQL injection vulnerability

  • CVE-2024-52724CriDec 2, 2024
    risk 0.64cvss 9.8epss 0.01

    ZZCMS 2023 was discovered to contain a SQL injection vulnerability in /q/show.php.

  • CVE-2024-53507CriNov 29, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability was discovered in Siyuan 3.1.11 in /getHistoryItems.

  • CVE-2024-53506CriNov 29, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the ids array parameter in /batchGetBlockAttrs.

  • CVE-2024-53505CriNov 29, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the id parameter at /getAssetContent.

  • CVE-2024-53504CriNov 29, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the notebook parameter in /searchHistory.

  • CVE-2024-50942CriNov 26, 2024
    risk 0.64cvss 9.8epss 0.01

    qiwen-file v1.4.0 was discovered to contain a SQL injection vulnerability via the component /mapper/NoticeMapper.xml.

  • CVE-2024-53438CriNov 22, 2024
    risk 0.64cvss 9.8epss 0.01

    EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into the SQL query without proper sanitization or validation, allowing attackers to execute…

  • CVE-2024-48072CriNov 19, 2024
    risk 0.64cvss 9.8epss 0.00

    Weaver Ecology v9.* was discovered to contain a SQL injection vulnerability via the component /mobilemode/Action.jsp?invoker=com.weaver.formmodel.mobile.mec.servlet.MECAction&action=getFieldTriggerValue&searchField=*&fromTable=HrmResourceManager&whereClause=1%3d1&triggerCondition…

  • CVE-2024-52675CriNov 19, 2024
    risk 0.64cvss 9.8epss 0.01

    SourceCodester Sentiment Based Movie Rating System 1.0 is vulnerable to SQL Injection in /msrps/movies.php.

  • CVE-2024-44756CriNov 18, 2024
    risk 0.64cvss 9.8epss 0.00

    NUS-M9 ERP Management Software v3.0.0 was discovered to contain a SQL injection vulnerability via the usercode parameter at /UserWH/checkLogin.

  • CVE-2024-50724CriNov 15, 2024
    risk 0.64cvss 9.8epss 0.00

    KASO v9.0 was discovered to contain a SQL injection vulnerability via the person_id parameter at /cardcase/editcard.jsp.

  • CVE-2024-50823CriNov 14, 2024
    risk 0.64cvss 9.8epss 0.00

    A SQL Injection vulnerability was found in /admin/login.php in kashipara E-learning Management System Project 1.0 via the username and password parameters.

  • CVE-2024-50833CriNov 14, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability was found in /login.php in KASHIPARA E-learning Management System Project 1.0 via the username and password parameters.

  • CVE-2024-44546CriNov 11, 2024
    risk 0.64cvss 9.8epss 0.00

    Powerjob >= 3.20 is vulnerable to SQL injection via the version parameter.

  • CVE-2024-50989CriNov 11, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /omrs/admin/search.php in PHPGurukul Online Marriage Registration System v1.0 allows an attacker to execute arbitrary SQL commands via the "searchdata " parameter.

  • CVE-2024-11020CriNov 11, 2024
    risk 0.64cvss 9.8epss 0.00

    Webopac from Grand Vice info has a SQL Injection vulnerability, allowing unauthenticated remote attacks to inject arbitrary SQL commands to read, modify, and delete database contents.

  • CVE-2024-11016CriNov 11, 2024
    risk 0.64cvss 9.8epss 0.01

    Webopac from Grand Vice info has a SQL Injection vulnerability, allowing unauthenticated remote attacks to inject arbitrary SQL commands to read, modify, and delete database contents.

  • CVE-2024-51211CriNov 8, 2024
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is due to improper input validation of the $username_stn_id parameter, which can be manipulated by an attacker to inject arbitrary SQL commands.

  • CVE-2024-50766CriNov 7, 2024
    risk 0.64cvss 9.8epss 0.01

    SourceCodester Survey Application System 1.0 is vulnerable to SQL Injection in takeSurvey.php via the id parameter.