VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 75 of 1,043
  • CVE-2024-25897CriFeb 21, 2024
    risk 0.64cvss 9.8epss 0.02

    ChurchCRM 5.5.0 FRCatalog.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.

  • CVE-2024-25894CriFeb 21, 2024
    risk 0.64cvss 9.8epss 0.01

    ChurchCRM 5.5.0 /EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EventCount POST parameter.

  • CVE-2024-0610CriFeb 17, 2024
    risk 0.64cvss 9.8epss 0.01

    The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'MerchantReference' parameter in all versions up to, and including, 1.6.5.1 due to insufficient escaping on the user supplied parameter and lack of…

  • CVE-2024-25320CriFeb 16, 2024
    risk 0.64cvss 9.8epss 0.01

    Tongda OA v2017 and up to v11.9 was discovered to contain a SQL injection vulnerability via the $AFF_ID parameter at /affair/delete.php.

  • CVE-2023-7081CriFeb 15, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in POSTAHSİL Online Payment System allows SQL Injection. This issue affects Online Payment System: before 14.02.2024.

  • CVE-2023-5155CriFeb 15, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Utarit Information Technologies SoliPay Mobile App allows SQL Injection. This issue affects SoliPay Mobile App: before 5.0.8.

  • CVE-2024-26264CriFeb 15, 2024
    risk 0.64cvss 9.8epss 0.01

    EBM Technologies RISWEB's specific query function parameter does not properly restrict user input, and this feature page is accessible without login. This allows remote attackers to inject SQL commands without authentication, enabling them to read, modify, and delete database…

  • CVE-2024-25223CriFeb 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Simple Admin Panel App v1.0 was discovered to contain a SQL injection vulnerability via the orderID parameter at /adminView/viewEachOrder.php.

  • CVE-2024-25222CriFeb 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the projectID parameter at /TaskManager/EditProject.php.

  • CVE-2024-25220CriFeb 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the taskID parameter at /TaskManager/EditTask.php.

  • CVE-2024-25217CriFeb 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Online Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /omos/?p=products/view_product.

  • CVE-2024-25216CriFeb 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the mailud parameter at /aprocess.php.

  • CVE-2024-25215CriFeb 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the pwd parameter at /aprocess.php.

  • CVE-2024-25214CriFeb 14, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Employee Managment System v1.0 allows attackers to bypass authentication via injecting a crafted payload into the E-mail and Password parameters at /alogin.html.

  • CVE-2024-25211CriFeb 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the category parameter at /endpoint/delete_category.php.

  • CVE-2024-25210CriFeb 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the expense parameter at /endpoint/delete_expense.php.

  • CVE-2024-25209CriFeb 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Barangay Population Monitoring System 1.0 was discovered to contain a SQL injection vulnerability via the resident parameter at /endpoint/delete-resident.php.

  • CVE-2023-6441CriFeb 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UNI-PA University Marketing & Computer Internet Trade Inc. University Information System allows SQL Injection. This issue affects University Information System: before…

  • CVE-2024-24142CriFeb 13, 2024
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester School Task Manager 1.0 allows SQL Injection via the 'subject' parameter.

  • CVE-2024-22923CriFeb 13, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in adv radius v.2.2.5 allows a local attacker to execute arbitrary code via a crafted script.