VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (12,807)

page 580 of 641
  • CVE-2021-37558CriAug 3, 2021
    risk 0.00cvss 9.8epss 0.02

    A SQL injection vulnerability in a MediaWiki script in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote unauthenticated attackers to execute arbitrary SQL commands via the host_name and service_description parameters. The vulnerability can be exploited only when a…

  • CVE-2021-23405HigJul 9, 2021
    risk 0.00cvss 8.3epss 0.02

    This affects the package pimcore/pimcore before 10.0.7. This issue exists due to the absence of check on the storeId parameter in the method collectionsActionGet and groupsActionGet method within the ClassificationstoreController class.

  • CVE-2021-32615CriMay 13, 2021
    risk 0.00cvss 9.8epss 0.02

    Piwigo 11.4.0 allows admin/user_list_backend.php order[0][dir] SQL Injection.

  • CVE-2020-15153HigApr 30, 2021
    risk 0.00cvss 8.2epss 0.02

    Ampache before version 4.2.2 allows unauthenticated users to perform SQL injection. Refer to the referenced GitHub Security Advisory for details and a workaround. This is fixed in version 4.2.2 and the development branch.

  • CVE-2020-24617HigFeb 19, 2021
    risk 0.00cvss 8.8epss 0.01

    Mailtrain through 1.24.1 allows SQL Injection in statsClickedSubscribersByColumn in lib/models/campaigns.js via /campaigns/clicked/ajax because variable column names are not properly escaped.

  • CVE-2021-21263HigJan 19, 2021
    risk 0.00cvss 7.2epss 0.02

    Laravel is a web application framework. Versions of Laravel before 6.20.11, 7.30.2 and 8.22.1 contain a query binding exploitation. This same exploit applies to the illuminate/database package which is used by Laravel. If a request is crafted where a field that is normally a…

  • CVE-2020-29437HigJan 5, 2021
    risk 0.00cvss 8.1epss 0.03

    SQL injection in the Buzz module of OrangeHRM through 4.6 allows remote authenticated attackers to execute arbitrary SQL commands via the orangehrmBuzzPlugin/lib/dao/BuzzDao.php loadMorePostsForm[profileUserId] parameter to the buzz/loadMoreProfile endpoint.

  • CVE-2020-21665HigNov 17, 2020
    risk 0.00cvss 7.2epss 0.01

    In fastadmin V1.0.0.20191212_beta, when a user with administrator rights has logged in, a malicious parameter can be passed for SQL injection in URL /admin/ajax/weigh.

  • CVE-2020-7759MedOct 30, 2020
    risk 0.00cvss 6.5epss 0.01

    The package pimcore/pimcore from 6.7.2 and before 6.8.3 are vulnerable to SQL Injection in data classification functionality in ClassificationstoreController. This can be exploited by sending a specifically-crafted input in the relationIds parameter as demonstrated by the…

  • CVE-2020-15226MedOct 7, 2020
    risk 0.00cvss 5.0epss 0.01

    In GLPI before version 9.5.2, there is a SQL Injection in the API's search function. Not only is it possible to break the SQL syntax, but it is also possible to utilise a UNION SELECT query to reflect sensitive information such as the current database version, or database user.…

  • CVE-2020-15176HigOct 7, 2020
    risk 0.00cvss 8.7epss 0.01

    In GLPI before version 9.5.2, when supplying a back tick in input that gets put into a SQL query,the application does not escape or sanitize allowing for SQL Injection to occur. Leveraging this vulnerability an attacker is able to exfiltrate sensitive information like passwords,…

  • CVE-2020-15108HigJul 17, 2020
    risk 0.00cvss 7.1epss 0.01

    In glpi before 9.5.1, there is a SQL injection for all usages of "Clone" feature. This has been fixed in 9.5.1.

  • CVE-2020-13380CriJul 1, 2020
    risk 0.00cvss 9.8epss 0.02

    openSIS before 7.4 allows SQL Injection.

  • CVE-2020-13433CriMay 24, 2020
    risk 0.00cvss 9.8epss 0.01

    Jason2605 AdminPanel 4.0 allows SQL Injection via the editPlayer.php hidden parameter.

  • CVE-2020-11004HigApr 24, 2020
    risk 0.00cvss 7.7epss 0.01

    SQL Injection was discovered in Admidio before version 3.3.13. The main cookie parameter is concatenated into a SQL query without any input validation/sanitization, thus an attacker without logging in, can send a GET request with arbitrary SQL queries appended to the cookie…

  • CVE-2020-8638CriApr 3, 2020
    risk 0.00cvss 9.8epss 0.02

    A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in planUrgency.php via the urgency parameter.

  • CVE-2020-8637CriApr 3, 2020
    risk 0.00cvss 9.8epss 0.03

    A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes.php via the node_id parameter.

  • CVE-2020-5292HigMar 31, 2020
    risk 0.00cvss 8.7epss 0.01

    Leantime before versions 2.0.15 and 2.1-beta3 has a SQL Injection vulnerability. The impact is high. Malicious users/attackers can execute arbitrary SQL queries negatively affecting the confidentiality, integrity, and availability of the site. Attackers can exfiltrate data like…

  • CVE-2020-10563CriMar 13, 2020
    risk 0.00cvss 9.8epss 0.02

    An issue was discovered in DEVOME GRR before 3.4.1c. frmcontactlist.php mishandles a SQL query.

  • CVE-2019-17647CriMar 5, 2020
    risk 0.00cvss 9.8epss 0.02

    An issue was discovered in Centreon before 2.8.30, 18.10.8, 19.04.5, and 19.10.2. SQL Injection exists via the include/monitoring/status/Hosts/xml/hostXML.php instance parameter.