VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,424)

page 730 of 1,022
  • CVE-2024-28560MedMar 22, 2024
    risk 0.35cvss 5.4epss 0.00

    SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the deleteArea() function of the Address.php component.

  • CVE-2024-24099MedFeb 27, 2024
    risk 0.35cvss 5.4epss 0.00

    Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Employment Status Information Update.

  • CVE-2023-45860MedFeb 16, 2024
    risk 0.35cvss 6.5epss 0.01

    In Hazelcast Platform through 5.3.4, a security issue exists within the SQL mapping for the CSV File Source connector. This issue arises from inadequate permission checking, which could enable unauthorized clients to access data from files stored on a member's filesystem.

  • CVE-2023-44294MedFeb 14, 2024
    risk 0.35cvss 5.4epss 0.00

    In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), a security concern has been identified, where a malicious user with a valid User session may inject malicious content in filters of Collection Rest API. This…

  • CVE-2023-44293MedFeb 14, 2024
    risk 0.35cvss 5.4epss 0.00

    In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), a security concern has been identified, where a malicious user with a valid User session may inject malicious content in filters of IP Range Rest API. This…

  • CVE-2023-49736MedDec 19, 2023
    risk 0.35cvss 6.5epss 0.01

    A where_in JINJA macro allows users to specify a quote, which combined with a carefully crafted statement would allow for SQL injection in Apache Superset.This issue affects Apache Superset: before 2.1.2, from 3.0.0 before 3.0.2. Users are recommended to upgrade to version…

  • CVE-2023-43377MedSep 20, 2023
    risk 0.35cvss 5.4epss 0.00

    A cross-site scripting (XSS) vulnerability in /hoteldruid/visualizza_contratto.php of Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the destinatario_email1 parameter.

  • CVE-2023-0620MedMar 30, 2023
    risk 0.35cvss 6.5epss 0.00

    HashiCorp Vault and Vault Enterprise versions 0.8.0 through 1.13.1 are vulnerable to an SQL injection attack when configuring the Microsoft SQL (MSSQL) Database Storage Backend. When configuring the MSSQL plugin through the local, certain parameters are not sanitized when passed…

  • CVE-2022-41703MedJan 16, 2023
    risk 0.35cvss 5.4epss 0.01

    A vulnerability in the SQL Alchemy connector of Apache Superset allows an authenticated user with read access to a specific database to add subqueries to the WHERE and HAVING fields referencing tables on the same database that the user should not have access to, despite the user…

  • CVE-2022-39072MedJan 6, 2023
    risk 0.35cvss 5.4epss 0.00

    There is a SQL injection vulnerability in Some ZTE Mobile Internet products. Due to insufficient validation of the input parameters of the SNTP interface, an authenticated attacker could use the vulnerability to execute stored XSS attacks.

  • CVE-2022-33875MedDec 6, 2022
    risk 0.35cvss 5.4epss 0.01

    An improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability in Fortinet FortiADC version 7.1.0, version 7.0.0 through 7.0.2 and version 6.2.4 and below allows an authenticated attacker to execute unauthorized code or commands via…

  • CVE-2022-20867MedNov 4, 2022
    risk 0.35cvss 5.4epss 0.01

    A vulnerability in web-based management interface of the of Cisco Email Security Appliance and Cisco Secure Email and Web Manager could allow an authenticated, remote attacker to conduct SQL injection attacks as root on an affected system. The attacker must have the credentials…

  • CVE-2020-15333MedSep 29, 2022
    risk 0.35cvss 5.3epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows attackers to discover accounts via MySQL "select * from Administrator_users" and "select * from Users_users" requests.

  • CVE-2022-26120MedJul 18, 2022
    risk 0.35cvss 5.4epss 0.01

    Multiple improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerabilities [CWE-89] in FortiADC management interface 7.0.0 through 7.0.1, 5.0.0 through 6.2.2 may allow an authenticated attacker to execute unauthorized code or commands via…

  • CVE-2022-20786MedApr 21, 2022
    risk 0.35cvss 5.4epss 0.01

    A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to…

  • CVE-2022-0842MedMar 23, 2022
    risk 0.35cvss 5.4epss 0.01

    A blind SQL injection vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote authenticated attacker to potentially obtain information from the ePO database. The data obtained is dependent on the privileges the attacker has and to…

  • CVE-2021-42633MedFeb 2, 2022
    risk 0.35cvss 5.3epss 0.02

    PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to SQL Injection, which may allow an attacker to access additional audit records.

  • CVE-2022-23857MedJan 24, 2022
    risk 0.35cvss 6.5epss 0.01

    model/criteria/criteria.go in Navidrome before 0.47.5 is vulnerable to SQL injection attacks when processing crafted Smart Playlists. An authenticated user could abuse this to extract arbitrary data from the database, including the user table (which contains sensitive…

  • CVE-2021-25037MedJan 17, 2022
    risk 0.35cvss 6.5epss 0.01

    The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discovered during an internal audit by the Jetpack Scan team, and could grant attackers access to privileged information from the affected site’s database (e.g.,…

  • CVE-2021-29099MedJun 7, 2021
    risk 0.35cvss 5.3epss 0.01

    A SQL injection vulnerability exists in some configurations of ArcGIS Server versions 10.8.1 and earlier. Specially crafted web requests can expose information that is not intended to be disclosed (not customer datasets). Web Services that use file based data sources (file…