VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,424)

page 729 of 1,022
  • CVE-2024-35468MedMay 30, 2024
    risk 0.35cvss 5.4epss 0.00

    A SQL injection vulnerability in /hrm/index.php in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.

  • CVE-2024-35548MedMay 28, 2024
    risk 0.35cvss 5.4epss 0.00

    A SQL injection vulnerability in Mybatis plus versions below 3.5.6 allows remote attackers to obtain database information via a Boolean blind injection. NOTE: the vendor's position is that this can only occur in a misconfigured application; the documentation discusses how to…

  • CVE-2024-33807MedMay 28, 2024
    risk 0.35cvss 5.4epss 0.00

    A SQL injection vulnerability in /model/get_teacher_timetable.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the grade parameter.

  • CVE-2024-33803MedMay 28, 2024
    risk 0.35cvss 5.4epss 0.00

    A SQL injection vulnerability in /model/get_exam.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.

  • CVE-2024-35085MedMay 23, 2024
    risk 0.35cvss 5.4epss 0.00

    J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in ProcessDefinitionMapper.xml.

  • CVE-2023-24204MedMay 14, 2024
    risk 0.35cvss 5.4epss 0.01

    SQL injection vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitrary code via the name parameter in get-quote.php.

  • CVE-2024-22856MedApr 22, 2024
    risk 0.35cvss 5.4epss 0.00

    A SQL injection vulnerability via the Save Favorite Search function in Axefinance Axe Credit Portal >= v.3.0 allows authenticated attackers to execute unintended queries and disclose sensitive information from DB tables via crafted requests.

  • CVE-2023-45503MedApr 15, 2024
    risk 0.35cvss 5.3epss 0.01

    SQL Injection vulnerability in Macrob7 Macs CMS 1.1.4f, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain sensitive information via crafted payload to resetPassword, forgotPasswordProcess, saveUser, saveRole,…

  • CVE-2024-29386MedApr 4, 2024
    risk 0.35cvss 5.4epss 0.00

    projeqtor up to 11.2.0 was discovered to contain a SQL injection vulnerability via the component /view/criticalResourceExport.php.

  • CVE-2024-30866MedApr 1, 2024
    risk 0.35cvss 5.4epss 0.00

    netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /3g/menu.php.

  • CVE-2024-29239MedMar 28, 2024
    risk 0.35cvss 5.4epss 0.01

    Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Recording.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to read database containing…

  • CVE-2024-29238MedMar 28, 2024
    risk 0.35cvss 5.4epss 0.01

    Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to read database containing…

  • CVE-2024-29237MedMar 28, 2024
    risk 0.35cvss 5.4epss 0.01

    Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in ActionRule.Delete webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to read database containing non-sensitive…

  • CVE-2024-29236MedMar 28, 2024
    risk 0.35cvss 5.4epss 0.01

    Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in AudioPattern.Delete webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to read database containing…

  • CVE-2024-29235MedMar 28, 2024
    risk 0.35cvss 5.4epss 0.01

    Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in IOModule.EnumLog webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to read database containing non-sensitive…

  • CVE-2024-29234MedMar 28, 2024
    risk 0.35cvss 5.4epss 0.01

    Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Group.Save webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to read database containing non-sensitive…

  • CVE-2024-29233MedMar 28, 2024
    risk 0.35cvss 5.4epss 0.01

    Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Emap.Delete webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to read database containing non-sensitive…

  • CVE-2024-29232MedMar 28, 2024
    risk 0.35cvss 5.4epss 0.01

    Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Alert.Enum webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to read database containing non-sensitive…

  • CVE-2024-29230MedMar 28, 2024
    risk 0.35cvss 5.4epss 0.01

    Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in SnapShot.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to read database containing…

  • CVE-2024-29227MedMar 28, 2024
    risk 0.35cvss 5.4epss 0.01

    Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Layout.LayoutSave webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to read database containing non-sensitive…