VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 74 of 1,043
  • CVE-2024-1301CriMar 12, 2024
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in Badger Meter Monitool affecting versions 4.6.3 and earlier. A remote attacker could send a specially crafted SQL query to the server via the j_username parameter and retrieve the information stored in the database.

  • CVE-2024-25849CriMar 8, 2024
    risk 0.64cvss 9.8epss 0.01

    In the module "Make an offer" (makeanoffer) <= 1.7.1 from PrestaToolKit for PrestaShop, a guest can perform SQL injection via MakeOffers::checkUserExistingOffer()` and `MakeOffers::addUserOffer()` .

  • CVE-2024-25845CriMar 8, 2024
    risk 0.64cvss 9.8epss 0.01

    In the module "CD Custom Fields 4 Orders" (cdcustomfields4orders) <= 1.0.0 from Cleanpresta.com for PrestaShop, a guest can perform SQL injection in affected versions.

  • CVE-2023-41014CriMar 7, 2024
    risk 0.64cvss 9.8epss 0.01

    code-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via the Username parameter for "Employer."

  • CVE-2023-49989CriMar 7, 2024
    risk 0.64cvss 9.8epss 0.01

    Hotel Booking Management v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at update.php.

  • CVE-2023-49970CriMar 5, 2024
    risk 0.64cvss 9.8epss 0.01

    Customer Support System v1 was discovered to contain a SQL injection vulnerability via the subject parameter at /customer_support/ajax.php?action=save_ticket.

  • CVE-2023-49547CriMar 5, 2024
    risk 0.64cvss 9.8epss 0.01

    Customer Support System v1 was discovered to contain a SQL injection vulnerability via the username parameter at /customer_support/ajax.php?action=login.

  • CVE-2024-1981CriFeb 29, 2024
    risk 0.64cvss 9.8epss 0.01

    The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to SQL Injection via the 'table_prefix' parameter in version 0.9.68 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…

  • CVE-2024-25833CriFeb 29, 2024
    risk 0.64cvss 9.8epss 0.03

    F-logic DataCube3 v1.0 is vulnerable to unauthenticated SQL injection, which could allow an unauthenticated malicious actor to execute arbitrary SQL queries in database.

  • CVE-2024-25422CriFeb 28, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive information via the SEMCMS_Menu.php component.

  • CVE-2024-25910CriFeb 28, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.

  • CVE-2024-1514CriFeb 28, 2024
    risk 0.64cvss 9.8epss 0.01

    The WP eCommerce plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'cart_contents' parameter in all versions up to, and including, 3.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…

  • CVE-2024-25843CriFeb 27, 2024
    risk 0.64cvss 9.8epss 0.01

    In the module "Import/Update Bulk Product from any Csv/Excel File Pro" (ba_importer) up to version 1.1.28 from Buy Addons for PrestaShop, a guest can perform SQL injection in affected versions.

  • CVE-2024-25400CriFeb 27, 2024
    risk 0.64cvss 9.8epss 0.01

    Subrion CMS 4.2.1 is vulnerable to SQL Injection via ia.core.mysqli.php. NOTE: this is disputed by multiple third parties because it refers to an HTTP request to a PHP file that only contains a class, without any mechanism for accepting external input, and the reportedly…

  • CVE-2024-24095CriFeb 27, 2024
    risk 0.64cvss 9.8epss 0.01

    Code-projects Simple Stock System 1.0 is vulnerable to SQL Injection.

  • CVE-2024-25247CriFeb 26, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in /app/api/controller/Store.php in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via latitude and longitude parameters.

  • CVE-2024-25248CriFeb 26, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in the orderGoodsDelivery() function in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via the order_id parameter.

  • CVE-2023-52153CriFeb 21, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability in /pmb/opac_css/includes/sessions.inc.php in PMB 7.4.7 and earlier allows remote unauthenticated attackers to inject arbitrary SQL commands via the PmbOpac-LOGIN cookie value.

  • CVE-2023-51828CriFeb 21, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability in /admin/convert/export.class.php in PMB 7.4.7 and earlier versions allows remote unauthenticated attackers to execute arbitrary SQL commands via the query parameter in get_next_notice function.

  • CVE-2023-37177CriFeb 21, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in PMB Services PMB v.7.4.7 and before allows a remote unauthenticated attacker to execute arbitrary code via the query parameter in the /admin/convert/export_z3950.php endpoint.