VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,812)

page 60 of 1,041
  • CVE-2024-27112CriSep 11, 2024
    risk 0.64cvss 9.8epss 0.00

    A unauthenticated SQL Injection has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use this vulnerability to gain access to the underlying database. The vulnerability has been remediated in version 1.52.02.

  • CVE-2024-6928CriSep 8, 2024
    risk 0.64cvss 9.8epss 0.03

    The Opti Marketing WordPress plugin through 2.0.9 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

  • CVE-2024-6924CriSep 8, 2024
    risk 0.64cvss 9.8epss 0.03

    The TrueBooker WordPress plugin before 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

  • CVE-2024-45771CriSep 6, 2024
    risk 0.64cvss 9.8epss 0.00

    RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the password parameter at /resource/runlogin.php.

  • CVE-2024-44839CriSep 6, 2024
    risk 0.64cvss 9.8epss 0.00

    RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the articleid parameter at /default/article.php.

  • CVE-2024-44838CriSep 6, 2024
    risk 0.64cvss 9.8epss 0.01

    RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the username parameter at /resource/runlogin.php.

  • CVE-2024-8395CriSep 5, 2024
    risk 0.64cvss 9.8epss 0.01

    FlyCASS CASS and KCM systems did not correctly filter SQL queries, which made them vulnerable to attack by outside attackers with no authentication.

  • CVE-2024-44727CriSep 5, 2024
    risk 0.64cvss 9.8epss 0.01

    Sourcecodehero Event Management System1.0 is vulnerable to SQL Injection via the parameter 'username' in /event/admin/login.php.

  • CVE-2024-8470CriSep 5, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /jobportal/admin/vacancy/controller.php, and retrieve all the information stored in it.

  • CVE-2024-8469CriSep 5, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobportal/admin/employee/index.php, and retrieve all the information stored in it.

  • CVE-2024-8468CriSep 5, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability, by which an attacker could send a specially designed query through search parameter in /jobportal/index.php, and retrieve all the information stored in it.

  • CVE-2024-8467CriSep 5, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobportal/admin/category/index.php, and retrieve all the information stored in it.

  • CVE-2024-8466CriSep 5, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /jobportal/admin/category/controller.php, and retrieve all the information stored in it.

  • CVE-2024-8465CriSep 5, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability, by which an attacker could send a specially designed query through user_id parameter in /jobportal/admin/user/controller.php, and retrieve all the information stored in it.

  • CVE-2024-8464CriSep 5, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability, by which an attacker could send a specially designed query through JOBREGID parameter in /jobportal/admin/applicants/controller.php, and retrieve all the information stored in it.

  • CVE-2024-7078CriSep 4, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Semtek Informatics Software Consulting Inc. Semtek Sempos allows SQL Injection. This issue affects Semtek Sempos: through 31072024.

  • CVE-2024-7076CriSep 4, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Semtek Informatics Software Consulting Inc. Semtek Sempos allows Blind SQL Injection. This issue affects Semtek Sempos: through 31072024.

  • CVE-2024-6926CriSep 4, 2024
    risk 0.64cvss 9.8epss 0.03

    The Viral Signup WordPress plugin through 2.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

  • CVE-2024-44921CriSep 3, 2024
    risk 0.64cvss 9.8epss 0.01

    SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac=del.

  • CVE-2024-6919CriSep 2, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Blind SQL Injection. This issue affects NACPremium: through 01082024.