VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,424)

page 736 of 1,022
  • CVE-2013-10011MedJan 12, 2023
    risk 0.34cvss 6.3epss 0.01

    A vulnerability was found in aeharding classroom-engagement-system and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to sql injection. The attack may be launched remotely. The name of the patch is…

  • CVE-2015-10008MedJan 2, 2023
    risk 0.34cvss 6.3epss 0.01

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in 82Flex WEIPDCRM. It has been classified as critical. This affects an unknown part. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The identifier of the patch is…

  • CVE-2020-36631MedDec 25, 2022
    risk 0.34cvss 6.3epss 0.01

    A vulnerability was found in barronwaffles dwc_network_server_emulator. It has been declared as critical. This vulnerability affects the function update_profile of the file gamespy/gs_database.py. The manipulation of the argument firstname/lastname leads to sql injection. The…

  • CVE-2022-45205MedNov 25, 2022
    risk 0.34cvss 5.3epss 0.01

    Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.

  • CVE-2022-39069MedNov 8, 2022
    risk 0.34cvss 5.3epss 0.00

    There is a SQL injection vulnerability in ZTE ZAIP-AIE. Due to lack of input verification by the server, an attacker could trigger an attack by building malicious requests. Exploitation of this vulnerability could cause the leakage of the current table content.

  • CVE-2022-3827MedNov 2, 2022
    risk 0.34cvss 6.3epss 0.01

    A vulnerability was found in centreon. It has been declared as critical. This vulnerability affects unknown code of the file formContactGroup.php of the component Contact Groups Form. The manipulation of the argument cg_id leads to sql injection. The attack can be initiated…

  • CVE-2022-3802MedNov 1, 2022
    risk 0.34cvss 6.3epss 0.01

    A vulnerability has been found in IBAX go-ibax and classified as critical. This vulnerability affects unknown code of the file /api/v2/open/rowsInfo. The manipulation of the argument where leads to sql injection. The attack can be initiated remotely. The exploit has been…

  • CVE-2022-3800MedNov 1, 2022
    risk 0.34cvss 6.3epss 0.02

    A vulnerability, which was classified as critical, has been found in IBAX go-ibax. Affected by this issue is some unknown functionality of the file /api/v2/open/rowsInfo. The manipulation of the argument table_name leads to sql injection. The attack may be launched remotely. The…

  • CVE-2022-3799MedNov 1, 2022
    risk 0.34cvss 6.3epss 0.01

    A vulnerability classified as critical was found in IBAX go-ibax. Affected by this vulnerability is an unknown functionality of the file /api/v2/open/tablesInfo. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the…

  • CVE-2022-3798MedNov 1, 2022
    risk 0.34cvss 6.3epss 0.01

    A vulnerability classified as critical has been found in IBAX go-ibax. Affected is an unknown function of the file /api/v2/open/tablesInfo. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may…

  • CVE-2020-11010MedApr 20, 2020
    risk 0.34cvss 6.3epss 0.01

    In Tortoise ORM before versions 0.15.23 and 0.16.6, various forms of SQL injection have been found for MySQL and when filtering or doing mass-updates on char/text fields. SQLite & PostgreSQL are only affected when filtering with contains, starts_with, or ends_with filters (and…

  • CVE-2026-7688MedMay 3, 2026
    risk 0.33cvss 5.0epss 0.00

    A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. This affects the function _checkValForAPI of the file htdocs/expedition/class/expedition.class.php of the component Shipments API Endpoint. The manipulation of the argument fields leads to sql injection. The attack…

  • CVE-2025-46053MedMay 15, 2025
    risk 0.33cvss 5.1epss 0.00

    A SQL Injection vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL commands and extract sensitive data by injecting a crafted payload into the ReportID and ReplaceReportID parameters within a POST request to /reportwriter/admin/ReportCreator.php

  • CVE-2023-33770MedMay 6, 2025
    risk 0.33cvss 5.1epss 0.00

    Real Estate Management System v1.0 was discovered to contain a SQL injection vulnerability via the message parameter at /contact.php.

  • CVE-2025-26047MedFeb 28, 2025
    risk 0.33cvss 5.1epss 0.00

    Loggrove v1.0 is vulnerable to SQL Injection in the read.py file.

  • CVE-2020-19248MedFeb 21, 2025
    risk 0.33cvss 5.1epss 0.00

    SQL Injection vulnerability in PbootCMS 1.4.1 in parsing if statements in templates, resulting in a malicious user's ability to contaminate template content by searching for page contamination URLs, thus triggering vulnerabilities when the program uses eval statements to parse…

  • CVE-2025-25993MedFeb 14, 2025
    risk 0.33cvss 5.1epss 0.00

    SQL Injection vulnerability in FeMiner wms wms 1.0 allows a remote attacker to obtain sensitive information via the parameter "itemid."

  • CVE-2025-25992MedFeb 14, 2025
    risk 0.33cvss 5.1epss 0.00

    SQL Injection vulnerability in FeMiner wms 1.0 allows a remote attacker to obtain sensitive information via the inquire_inout_item.php component.

  • CVE-2025-25991MedFeb 14, 2025
    risk 0.33cvss 5.1epss 0.00

    SQL Injection vulnerability in hooskcms v.1.7.1 allows a remote attacker to obtain sensitive information via the /install/index.php component.

  • CVE-2024-30872MedApr 1, 2024
    risk 0.33cvss 5.1epss 0.00

    netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /include/authrp.php.