VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,812)

page 58 of 1,041
  • CVE-2024-10687CriNov 5, 2024
    risk 0.64cvss 9.8epss 0.01

    The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons plugin for WordPress is vulnerable to time-based SQL Injection via the $collectedIds parameter in all versions up to, and including, 24.0.3…

  • CVE-2024-51327CriNov 4, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection in loginform.php in ProjectWorld's Travel Management System v1.0 allows remote attackers to bypass authentication via SQL Injection in the 'username' and 'password' fields.

  • CVE-2024-7456CriNov 1, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in the `/api/v1/external-users` route of lunary-ai/lunary version v1.4.2. The `order by` clause of the SQL query uses `sql.unsafe` without prior sanitization, allowing for SQL injection. The `orderByClause` variable is constructed without…

  • CVE-2024-51065CriOct 31, 2024
    risk 0.64cvss 9.8epss 0.01

    Phpgurukul Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in admin/index.php via the the username parameter.

  • CVE-2024-51064CriOct 31, 2024
    risk 0.64cvss 9.8epss 0.01

    Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection via the tid parameter to admin/queries.php.

  • CVE-2024-48356CriOct 28, 2024
    risk 0.64cvss 9.8epss 0.01

    LyLme Spage <=1.6.0 is vulnerable to SQL Injection via /admin/group.php.

  • CVE-2024-48465CriOct 28, 2024
    risk 0.64cvss 9.8epss 0.00

    The MRBS version 1.5.0 has an SQL injection vulnerability in the edit_entry_handler.php file, specifically in the rooms%5B%5D parameter

  • CVE-2024-48357CriOct 28, 2024
    risk 0.64cvss 9.8epss 0.01

    LyLme Spage 1.2.0 through 1.6.0 is vulnerable to SQL Injection via /admin/apply.php.

  • CVE-2024-10440CriOct 28, 2024
    risk 0.64cvss 9.8epss 0.01

    The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL command to read, modify, and delete database contents.

  • CVE-2024-48580CriOct 25, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the email parameter of the login request.

  • CVE-2024-44812CriOct 22, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Online Complaint Site v.1.0 allows a remote attacker to escalate privileges via the username and password parameters in the /admin.index.php component.

  • CVE-2024-48509CriOct 21, 2024
    risk 0.64cvss 9.8epss 0.01

    Learning with Texts (LWT) 2.0.3 is vulnerable to SQL Injection. This occurs when the application fails to properly sanitize user inputs, allowing attackers to manipulate SQL queries by injecting malicious SQL statements into URL parameters. By exploiting this vulnerability, an…

  • CVE-2016-15040CriOct 16, 2024
    risk 0.64cvss 9.8epss 0.01

    The Kento Post View Counter plugin for WordPress is vulnerable to SQL Injection via the 'kento_pvc_geo' parameter in versions up to, and including, 2.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…

  • CVE-2024-48411CriOct 15, 2024
    risk 0.64cvss 9.8epss 0.01

    itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to SQL Injection (SQLI) via a crafted payload to the val-email parameter in forget_password.php.

  • CVE-2024-48283CriOct 15, 2024
    risk 0.64cvss 9.8epss 0.01

    Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to SQL Injection in /admin//search-result.php via the searchkey parameter.

  • CVE-2024-9925CriOct 15, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in TAI Smart Factory's QPLANT SF version 1.0. Exploitation of this vulnerability could allow a remote attacker to retrieve all database information by sending a specially crafted SQL query to the ‘email’ parameter on the…

  • CVE-2024-9982CriOct 15, 2024
    risk 0.64cvss 9.8epss 0.01

    AIM LINE Marketing Platform from Esi Technology does not properly validate a specific query parameter. When the LINE Campaign Module is enabled, unauthenticated remote attackers can inject arbitrary FetchXml commands to read, modify, and delete database content.

  • CVE-2024-9972CriOct 15, 2024
    risk 0.64cvss 9.8epss 0.01

    Property Management System from ChanGate has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

  • CVE-2024-46535CriOct 14, 2024
    risk 0.64cvss 9.8epss 0.00

    Jepaas v7.2.8 was discovered to contain a SQL injection vulnerability via the orderSQL parameter at /homePortal/loadUserMsg.

  • CVE-2024-48255CriOct 14, 2024
    risk 0.64cvss 9.8epss 0.00

    Cloudlog 2.6.15 allows Oqrs.php get_station_info station_id SQL injection.