VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,861)

page 574 of 1,044
  • CVE-2023-52290HigJul 16, 2024
    risk 0.46cvss 8.1epss 0.01

    In streampark-console the list pages(e.g: application pages), users can sort page by field. This sort field is sent from the front-end to the back-end, and the SQL query is generated using this field. However, because this sort field isn't validated, there is a risk of SQL…

  • CVE-2024-36263HigJun 12, 2024
    risk 0.46cvss 8.1epss 0.01

    ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Core: all versions. As this project is retired, we do not plan to…

  • CVE-2024-32655HigMay 14, 2024
    risk 0.46cvss 8.1epss 0.02

    Npgsql is the .NET data provider for PostgreSQL. The `WriteBind()` method in `src/Npgsql/Internal/NpgsqlConnector.FrontendMessages.cs` uses `int` variables to store the message length and the sum of parameter lengths. Both variables overflow when the sum of parameter lengths…

  • CVE-2024-28714HigMar 28, 2024
    risk 0.46cvss 8.1epss 0.01

    SQL Injection vulnerability in CRMEB_Java e-commerce system v.1.3.4 allows an attacker to execute arbitrary code via the groupid parameter.

  • CVE-2024-25325HigMar 12, 2024
    risk 0.46cvss 7.1epss 0.00

    SQL injection vulnerability in Employee Management System v.1.0 allows a local attacker to obtain sensitive information via a crafted payload to the txtemail parameter in the login.php.

  • CVE-2024-28816HigMar 11, 2024
    risk 0.46cvss 7.1epss 0.00

    Student Information Chatbot a0196ab allows SQL injection via the username to the login function in index.php.

  • CVE-2024-27289HigMar 6, 2024
    risk 0.46cvss 8.1epss 0.01

    pgx is a PostgreSQL driver and toolkit for Go. Prior to version 4.18.2, SQL injection can occur when all of the following conditions are met: the non-default simple protocol is used; a placeholder for a numeric value must be immediately preceded by a minus; there must be a…

  • CVE-2024-25928HigFeb 23, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sitepact.This issue affects Sitepact: from n/a through 1.0.5.

  • CVE-2023-28788HigDec 20, 2023
    risk 0.46cvss 7.1epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Page Visit Counter Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress.This issue affects Advanced Page Visit Counter – Most Wanted Analytics Plugin for…

  • CVE-2023-25990HigNov 3, 2023
    risk 0.46cvss 7.1epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection.This issue affects Tutor LMS: from n/a through 2.1.10.

  • CVE-2023-26015HigNov 3, 2023
    risk 0.46cvss 7.1epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Chris Richardson MapPress Maps for WordPress mappress-google-maps-for-wordpress allows SQL Injection.This issue affects MapPress Maps for WordPress: from n/a through 2.85.4.

  • CVE-2023-39980HigSep 2, 2023
    risk 0.46cvss 7.1epss 0.01

    A vulnerability that allows the unauthorized disclosure of authenticated information has been identified in MXsecurity versions prior to v1.0.1. This vulnerability arises when special elements are not neutralized correctly, allowing remote attackers to alter SQL commands.

  • CVE-2023-4548MedAug 26, 2023
    risk 0.46cvss 6.3epss 0.32

    A vulnerability has been found in SPA-Cart eCommerce CMS 1.9.0.3. The impacted element is an unknown function of the file /search of the component GET Parameter Handler. Such manipulation of the argument filter[brandid] leads to sql injection. The attack may be performed from…

  • CVE-2023-33993HigAug 8, 2023
    risk 0.46cvss 7.1epss 0.01

    B1i module of SAP Business One - version 10.0, application allows an authenticated user with deep knowledge to send crafted queries over the network to read or modify the SQL data. On successful exploitation, the attacker can cause high impact on confidentiality, integrity and…

  • CVE-2023-26440HigAug 2, 2023
    risk 0.46cvss 7.1epss 0.00

    The cacheservice API could be abused to indirectly inject parameters with SQL syntax which was insufficiently sanitized and would later be executed when creating new cache groups. Attackers with access to a local or restricted network could perform arbitrary SQL queries. We have…

  • CVE-2023-25839HigJul 19, 2023
    risk 0.46cvss 7.0epss 0.00

    There is SQL injection vulnerability in Esri ArcGIS Insights Desktop for Mac and Windows version 2022.1 that may allow a local, authorized attacker to execute arbitrary SQL commands against the back-end database. The effort required to generate the crafted input required to…

  • CVE-2023-35782HigJun 16, 2023
    risk 0.46cvss 8.2epss 0.01

    The ipandlanguageredirect extension before 5.1.2 for TYPO3 allows SQL Injection.

  • CVE-2023-33967HigMay 31, 2023
    risk 0.46cvss 8.2epss 0.01

    EaseProbe is a tool that can do health/status checking. An SQL injection issue was discovered in EaseProbe before 2.1.0 when using MySQL/PostgreSQL data checking. This problem has been fixed in v2.1.0.

  • CVE-2023-27167MedMar 29, 2023
    risk 0.46cvss 6.5epss 0.08

    Suprema BioStar 2 v2.8.16 was discovered to contain a SQL injection vulnerability via the values parameter at /users/absence?search_month=1.

  • CVE-2022-41671HigNov 4, 2022
    risk 0.46cvss 7.0epss 0.00

    A CWE-89: Improper Neutralization of Special Elements used in SQL Command (‘SQL Injection’) vulnerability exists that allows adversaries with local user privileges to craft a malicious SQL query and execute as part of project migration which could result in execution of…