VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 67 of 1,043
  • CVE-2024-34994CriJun 19, 2024
    risk 0.64cvss 9.8epss 0.00

    In the module "Channable" (channable) up to version 3.2.1 from Channable for PrestaShop, a guest can perform SQL injection via `ChannableFeedModuleFrontController::postProcess()`.

  • CVE-2024-37831CriJun 14, 2024
    risk 0.64cvss 9.8epss 0.00

    Itsourcecode Payroll Management System 1.0 is vulnerable to SQL Injection in payroll_items.php via the ID parameter.

  • CVE-2024-37849CriJun 13, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability in itsourcecode Billing System 1.0 allows a local attacker to execute arbitrary code in process.php via the username parameter.

  • CVE-2024-1576CriJun 12, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in MegaBIP software allows attacker to obtain site administrator privileges, including access to the administration panel and the ability to change the administrator password. This issue affects MegaBIP software versions through 5.09.

  • CVE-2024-35305CriJun 10, 2024
    risk 0.64cvss 9.8epss 0.00

    Unauth Time-Based SQL Injection in API allows to exploit HTTP request Authorization header. This issue affects Pandora FMS: from 700 through <777.

  • CVE-2024-30163CriJun 7, 2024
    risk 0.64cvss 9.8epss 0.09

    Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\modules\front\store\_store::_categoryView() method, where user input passed through the filter request parameter is not properly sanitized before being used to…

  • CVE-2024-36673CriJun 7, 2024
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester Pharmacy/Medical Store Point of Sale System 1.0 is vulnerable SQL Injection via login.php. This vulnerability stems from inadequate validation of user inputs for the email and password parameters, allowing attackers to inject malicious SQL queries.

  • CVE-2024-36779CriJun 6, 2024
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester Stock Management System v1.0 is vulnerable to SQL Injection via editCategories.php.

  • CVE-2024-36393CriJun 6, 2024
    risk 0.64cvss 9.9epss 0.00

    SysAid - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

  • CVE-2024-5311CriJun 3, 2024
    risk 0.64cvss 9.8epss 0.01

    DigiWin EasyFlow .NET lacks validation for certain input parameters. An unauthenticated remote attacker can inject arbitrary SQL commands to read, modify, and delete database records.

  • CVE-2024-3200CriJun 1, 2024
    risk 0.64cvss 9.9epss 0.00

    The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'slug' attribute of the 'wpforo' shortcode in all versions up to, and including, 2.3.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…

  • CVE-2024-35469CriMay 30, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /hrm/user/ in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.

  • CVE-2024-35359CriMay 30, 2024
    risk 0.64cvss 9.8epss 0.00

    A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=view_item. Manipulating the argument id can result in SQL injection.

  • CVE-2024-35350CriMay 30, 2024
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /admin/?page=borrow/view_borrow. Manipulating the argument id can result in SQL injection.

  • CVE-2024-35349CriMay 30, 2024
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /admin/category/view_category.php. Manipulating the argument id can result in SQL injection.

  • CVE-2024-35355CriMay 30, 2024
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=delete_category. Manipulating the argument id can result in SQL injection.

  • CVE-2024-35354CriMay 30, 2024
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=save_category. Manipulating the argument id can result in SQL injection.

  • CVE-2024-1100CriMay 30, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Vadi Corporate Information Systems DIGIKENT GIS allows SQL Injection. This issue affects DIGIKENT GIS: through 2.23.5.

  • CVE-2024-35563CriMay 28, 2024
    risk 0.64cvss 9.8epss 0.00

    CDG-Server-V5.6.2.126.139 and earlier was discovered to contain a SQL injection vulnerability via the permissionId parameter in CDGTempPermissions.

  • CVE-2024-33808CriMay 28, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /model/get_timetable.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.