CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,424)
page 742 of 1,022| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-25288 | Med | 0.32 | 4.9 | 0.01 | Feb 21, 2024 | SLIMS (Senayan Library Management Systems) 9 Bulian v9.6.1 is vulnerable to SQL Injection via pop-scope-vocabolary.php. | ||
| CVE-2020-26630 | Med | 0.32 | 4.9 | 0.01 | Jan 10, 2024 | A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a special payload in the 'Doctor Specialization' field under the 'Go to Doctors' tab after logging in as an admin. | ||
| CVE-2020-26627 | Med | 0.32 | 4.9 | 0.01 | Jan 10, 2024 | A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a crafted payload entered into the 'Admin Remark' parameter under the 'Contact Us Queries -> Unread Query' tab. | ||
| CVE-2023-30867 | Med | 0.32 | 4.9 | 0.01 | Dec 15, 2023 | In the Streampark platform, when users log in to the system and use certain features, some pages provide a name-based fuzzy search, such as job names, role names, etc. The sql syntax :select * from table where jobName like '%jobName%'. However, the jobName field may receive… | ||
| CVE-2023-46025 | Med | 0.32 | 4.9 | 0.01 | Nov 14, 2023 | SQL Injection vulnerability in teacher-info.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers to obtain sensitive information via the 'editid' parameter. | ||
| CVE-2023-5322 | Med | 0.32 | 4.7 | 0.17 | Oct 1, 2023 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20151231. It has been rated as critical. Affected by this issue is some unknown functionality of the file /sysmanage/edit_manageadmin.php. The manipulation of the argument id leads to sql… | ||
| CVE-2023-43493 | Med | 0.32 | 4.9 | 0.01 | Sep 27, 2023 | SQL injection vulnerability in Item List page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with author or higher privilege to obtain sensitive information. | ||
| CVE-2023-39582 | Med | 0.32 | 4.9 | 0.01 | Sep 1, 2023 | SQL Injection vulnerability in Chamilo LMS v.1.11 thru v.1.11.20 allows a remote privileged attacker to obtain sensitive information via the import sessions functions. | ||
| CVE-2022-46047 | Med | 0.32 | 4.9 | 0.01 | Dec 13, 2022 | AeroCMS v0.0.1 is vulnerable to SQL Injection via the delete parameter. | ||
| CVE-2022-45536 | Med | 0.32 | 4.9 | 0.01 | Nov 22, 2022 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the id parameter at \admin\post_comments.php. This vulnerability allows attackers to access database information. | ||
| CVE-2022-45535 | Med | 0.32 | 4.9 | 0.01 | Nov 22, 2022 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the edit parameter at \admin\categories.php. This vulnerability allows attackers to access database information. | ||
| CVE-2022-45529 | Med | 0.32 | 4.9 | 0.01 | Nov 22, 2022 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the post_category_id parameter at \admin\includes\edit_post.php. This vulnerability allows attackers to access database information. | ||
| CVE-2022-43709 | Med | 0.32 | 4.9 | 0.01 | Nov 22, 2022 | MyBB 1.8.31 has a SQL injection vulnerability in the Admin CP's Users module allows remote authenticated users to modify the query string via direct user input or stored search filter settings. | ||
| CVE-2021-37823 | Med | 0.32 | 4.9 | 0.01 | Nov 3, 2022 | OpenCart 3.0.3.7 allows users to obtain database information or read server files through SQL injection in the background. | ||
| CVE-2022-43086 | Med | 0.32 | 4.9 | 0.01 | Nov 1, 2022 | Restaurant POS System v1.0 was discovered to contain a SQL injection vulnerability via update_customer.php. | ||
| CVE-2022-2137 | Med | 0.32 | 4.9 | 0.01 | Jul 22, 2022 | The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an unauthorized attacker to disclose information | ||
| CVE-2022-1691 | Med | 0.32 | 4.9 | 0.01 | Jun 8, 2022 | The Realty Workstation WordPress plugin before 1.0.15 does not sanitise and escape the trans_edit parameter before using it in a SQL statement when an agent edit a transaction, leading to an SQL injection | ||
| CVE-2022-1685 | Med | 0.32 | 4.9 | 0.01 | Jun 8, 2022 | The Five Minute Webshop WordPress plugin through 1.3.2 does not properly validate and sanitise the orderby parameter before using it in a SQL statement via the Manage Products admin page, leading to an SQL Injection | ||
| CVE-2020-19212 | Med | 0.32 | 4.9 | 0.01 | May 6, 2022 | SQL Injection vulnerability in admin/group_list.php in piwigo v2.9.5, via the group parameter to delete. | ||
| CVE-2021-21923 | Med | 0.32 | 4.9 | 0.01 | Dec 22, 2021 | A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘company_filter’ parameter with the administrative account or through cross-site request forgery. |
- risk 0.32cvss 4.9epss 0.01
SLIMS (Senayan Library Management Systems) 9 Bulian v9.6.1 is vulnerable to SQL Injection via pop-scope-vocabolary.php.
- risk 0.32cvss 4.9epss 0.01
A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a special payload in the 'Doctor Specialization' field under the 'Go to Doctors' tab after logging in as an admin.
- risk 0.32cvss 4.9epss 0.01
A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a crafted payload entered into the 'Admin Remark' parameter under the 'Contact Us Queries -> Unread Query' tab.
- risk 0.32cvss 4.9epss 0.01
In the Streampark platform, when users log in to the system and use certain features, some pages provide a name-based fuzzy search, such as job names, role names, etc. The sql syntax :select * from table where jobName like '%jobName%'. However, the jobName field may receive…
- risk 0.32cvss 4.9epss 0.01
SQL Injection vulnerability in teacher-info.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers to obtain sensitive information via the 'editid' parameter.
- risk 0.32cvss 4.7epss 0.17
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20151231. It has been rated as critical. Affected by this issue is some unknown functionality of the file /sysmanage/edit_manageadmin.php. The manipulation of the argument id leads to sql…
- risk 0.32cvss 4.9epss 0.01
SQL injection vulnerability in Item List page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with author or higher privilege to obtain sensitive information.
- risk 0.32cvss 4.9epss 0.01
SQL Injection vulnerability in Chamilo LMS v.1.11 thru v.1.11.20 allows a remote privileged attacker to obtain sensitive information via the import sessions functions.
- risk 0.32cvss 4.9epss 0.01
AeroCMS v0.0.1 is vulnerable to SQL Injection via the delete parameter.
- risk 0.32cvss 4.9epss 0.01
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the id parameter at \admin\post_comments.php. This vulnerability allows attackers to access database information.
- risk 0.32cvss 4.9epss 0.01
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the edit parameter at \admin\categories.php. This vulnerability allows attackers to access database information.
- risk 0.32cvss 4.9epss 0.01
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the post_category_id parameter at \admin\includes\edit_post.php. This vulnerability allows attackers to access database information.
- risk 0.32cvss 4.9epss 0.01
MyBB 1.8.31 has a SQL injection vulnerability in the Admin CP's Users module allows remote authenticated users to modify the query string via direct user input or stored search filter settings.
- risk 0.32cvss 4.9epss 0.01
OpenCart 3.0.3.7 allows users to obtain database information or read server files through SQL injection in the background.
- risk 0.32cvss 4.9epss 0.01
Restaurant POS System v1.0 was discovered to contain a SQL injection vulnerability via update_customer.php.
- risk 0.32cvss 4.9epss 0.01
The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an unauthorized attacker to disclose information
- risk 0.32cvss 4.9epss 0.01
The Realty Workstation WordPress plugin before 1.0.15 does not sanitise and escape the trans_edit parameter before using it in a SQL statement when an agent edit a transaction, leading to an SQL injection
- risk 0.32cvss 4.9epss 0.01
The Five Minute Webshop WordPress plugin through 1.3.2 does not properly validate and sanitise the orderby parameter before using it in a SQL statement via the Manage Products admin page, leading to an SQL Injection
- risk 0.32cvss 4.9epss 0.01
SQL Injection vulnerability in admin/group_list.php in piwigo v2.9.5, via the group parameter to delete.
- risk 0.32cvss 4.9epss 0.01
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘company_filter’ parameter with the administrative account or through cross-site request forgery.