VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 72 of 1,043
  • CVE-2024-28556CriApr 15, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to admin-manage-user.php.

  • CVE-2024-3704CriApr 12, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection Vulnerability has been found on OpenGnsys product affecting version 1.1.1d (Espeto). This vulnerability allows an attacker to inject malicious SQL code into login page to bypass it or even retrieve all the information stored in the database.

  • CVE-2024-31678CriApr 11, 2024
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester Loan Management System v1.0 is vulnerable to SQL Injection via the "password" parameter in the "login.php" file.

  • CVE-2024-2804CriApr 9, 2024
    risk 0.64cvss 9.8epss 0.01

    The Network Summary plugin for WordPress is vulnerable to SQL Injection via the 'category' parameter in all versions up to, and including, 2.0.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…

  • CVE-2024-30998CriApr 3, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in PHPGurukul Men Salon Management System v.2.0, allows remote attackers to execute arbitrary code and obtain sensitive information via the email parameter in the index.php component.

  • CVE-2024-29432CriApr 2, 2024
    risk 0.64cvss 9.8epss 0.01

    Alldata v0.4.6 was discovered to contain a SQL injection vulnerability via the tablename parameter at /data/masterdata/datas.

  • CVE-2024-1863CriApr 1, 2024
    risk 0.64cvss 9.8epss 0.01

    Sante PACS Server Token Endpoint SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante PACS Server. Authentication is not required to exploit this vulnerability. The specific…

  • CVE-2024-30867CriApr 1, 2024
    risk 0.64cvss 9.8epss 0.01

    netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_virtual_site_info.php.

  • CVE-2024-30865CriApr 1, 2024
    risk 0.64cvss 9.8epss 0.01

    netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_user_login.php.

  • CVE-2024-23538CriMar 29, 2024
    risk 0.64cvss 9.9epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to version 1.8.5 or 1.9.0, which fix the issue.

  • CVE-2023-6191CriMar 29, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Egehan Security WebPDKS allows SQL Injection. This issue affects WebPDKS: through 20240329. NOTE: The vendor was contacted early about this disclosure but did not respond in…

  • CVE-2023-6173CriMar 27, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeoSOFT Software TeoBASE allows SQL Injection. This issue affects TeoBASE: through 27032024. NOTE: The vendor was contacted early about this disclosure but did not respond in…

  • CVE-2024-29303CriMar 26, 2024
    risk 0.64cvss 9.8epss 0.01

    The delete admin users function of SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection

  • CVE-2024-28421CriMar 25, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Razor 0.8.0 allows a remote attacker to escalate privileges via the ChannelModel::updateapk method of the channelmodle.php

  • CVE-2024-2865CriMar 25, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mergen Software Quality Management System allows SQL Injection. This issue affects Quality Management System: through 25032024.

  • CVE-2024-28393CriMar 25, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in scalapay v.1.2.41 and before allows a remote attacker to escalate privileges via the ScalapayReturnModuleFrontController::postProcess() method.

  • CVE-2024-2724CriMar 22, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in the CIGESv2 system, through /ajaxServiciosAtencion.php, in the 'idServicio' parameter. The exploitation of this vulnerability could allow a remote user to retrieve all data stored in the database by sending a specially crafted SQL query.

  • CVE-2024-2723CriMar 22, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in the CIGESv2 system, through /ajaxSubServicios.php, in the 'idServicio' parameter. The exploitation of this vulnerability could allow a remote user to retrieve all data stored in the database by sending a specially crafted SQL query.

  • CVE-2024-2722CriMar 22, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in the CIGESv2 system, through /ajaxConfigTotem.php, in the 'id' parameter. The exploitation of this vulnerability could allow a remote user to retrieve all data stored in the database by sending a specially crafted SQL query.

  • CVE-2024-29275CriMar 22, 2024
    risk 0.64cvss 9.8epss 0.05

    SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code and obtain sensitive information via the id parameter in class.php.