CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 76 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-23763 | Cri | 0.64 | 9.8 | 0.01 | Feb 12, 2024 | SQL Injection vulnerability in Gambio through 4.9.2.0 allows attackers to run arbitrary SQL commands via crafted GET request using modifiers[attribute][] parameter. | ||
| CVE-2024-25316 | Cri | 0.64 | 9.8 | 0.01 | Feb 9, 2024 | Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'eid' parameter in Hotel/admin/usersettingdel.php?eid=2. | ||
| CVE-2024-25315 | Cri | 0.64 | 9.8 | 0.01 | Feb 9, 2024 | Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'rid' parameter in Hotel/admin/roombook.php?rid=2. | ||
| CVE-2024-25314 | Cri | 0.64 | 9.8 | 0.01 | Feb 9, 2024 | Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'sid' parameter in Hotel/admin/show.php?sid=2. | ||
| CVE-2024-25307 | Cri | 0.64 | 9.8 | 0.01 | Feb 9, 2024 | Code-projects Cinema Seat Reservation System 1.0 allows SQL Injection via the 'id' parameter at "/Cinema-Reservation/booking.php?id=1." | ||
| CVE-2024-25302 | Cri | 0.64 | 9.8 | 0.01 | Feb 9, 2024 | Sourcecodester Event Student Attendance System 1.0, allows SQL Injection via the 'student' parameter. | ||
| CVE-2023-6677 | Cri | 0.64 | 9.8 | 0.01 | Feb 9, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oduyo Financial Technology Online Collection allows SQL Injection. This issue affects Online Collection: before v.1.0.2. | ||
| CVE-2024-24308 | Cri | 0.64 | 9.8 | 0.01 | Feb 9, 2024 | SQL Injection vulnerability in Boostmyshop (boostmyshopagent) module for Prestashop versions 1.1.9 and before, allows remote attackers to escalate privileges and obtain sensitive information via changeOrderCarrier.php, relayPoint.php, and shippingConfirmation.php. | ||
| CVE-2023-50026 | Cri | 0.64 | 9.8 | 0.01 | Feb 9, 2024 | SQL injection vulnerability in Presta Monster "Multi Accessories Pro" (hsmultiaccessoriespro) module for PrestaShop versions 5.1.1 and before, allows remote attackers to escalate privileges and obtain sensitive information via the method HsAccessoriesGroupProductAbstract::getAcce… | ||
| CVE-2023-46350 | Cri | 0.64 | 9.8 | 0.01 | Feb 9, 2024 | SQL injection vulnerability in InnovaDeluxe "Manufacturer or supplier alphabetical search" (idxrmanufacturer) module for PrestaShop versions 2.0.4 and before, allows remote attackers to escalate privileges and obtain sensitive information via the methods… | ||
| CVE-2024-24213 | Cri | 0.64 | 9.8 | 0.01 | Feb 8, 2024 | Supabase PostgreSQL v15.1 was discovered to contain a SQL injection vulnerability via the component /pg_meta/default/query. NOTE: the vendor's position is that this is an intended feature; also, it exists in the Supabase dashboard product, not the Supabase PostgreSQL product.… | ||
| CVE-2023-50061 | Cri | 0.64 | 9.8 | 0.01 | Feb 8, 2024 | PrestaShop Op'art Easy Redirect >= 1.3.8 and <= 1.3.12 is vulnerable to SQL Injection via Oparteasyredirect::hookActionDispatcher(). | ||
| CVE-2024-1207 | Cri | 0.64 | 9.8 | 0.03 | Feb 8, 2024 | The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on… | ||
| CVE-2024-24021 | Cri | 0.64 | 9.8 | 0.01 | Feb 8, 2024 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, limit, and sort parameters to perform SQL injection via /novel/userFeedback/list. | ||
| CVE-2024-24017 | Cri | 0.64 | 9.8 | 0.01 | Feb 8, 2024 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /common/dict/list | ||
| CVE-2024-24014 | Cri | 0.64 | 9.8 | 0.01 | Feb 8, 2024 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /novel/author/list | ||
| CVE-2024-24003 | Cri | 0.64 | 9.8 | 0.01 | Feb 8, 2024 | jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findInOutMaterialCount() function of jshERP does not filter `column` and `order` parameters well enough, and an attacker can construct malicious payload… | ||
| CVE-2024-24023 | Cri | 0.64 | 9.8 | 0.01 | Feb 8, 2024 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, limit, and sort parameters to perform SQL injection via /novel/bookContent/list. | ||
| CVE-2024-24018 | Cri | 0.64 | 9.8 | 0.01 | Feb 8, 2024 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL injection via /system/dataPerm/list | ||
| CVE-2024-24133 | Cri | 0.64 | 9.8 | 0.01 | Feb 7, 2024 | Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page. |
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in Gambio through 4.9.2.0 allows attackers to run arbitrary SQL commands via crafted GET request using modifiers[attribute][] parameter.
- risk 0.64cvss 9.8epss 0.01
Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'eid' parameter in Hotel/admin/usersettingdel.php?eid=2.
- risk 0.64cvss 9.8epss 0.01
Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'rid' parameter in Hotel/admin/roombook.php?rid=2.
- risk 0.64cvss 9.8epss 0.01
Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'sid' parameter in Hotel/admin/show.php?sid=2.
- risk 0.64cvss 9.8epss 0.01
Code-projects Cinema Seat Reservation System 1.0 allows SQL Injection via the 'id' parameter at "/Cinema-Reservation/booking.php?id=1."
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Event Student Attendance System 1.0, allows SQL Injection via the 'student' parameter.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oduyo Financial Technology Online Collection allows SQL Injection. This issue affects Online Collection: before v.1.0.2.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in Boostmyshop (boostmyshopagent) module for Prestashop versions 1.1.9 and before, allows remote attackers to escalate privileges and obtain sensitive information via changeOrderCarrier.php, relayPoint.php, and shippingConfirmation.php.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in Presta Monster "Multi Accessories Pro" (hsmultiaccessoriespro) module for PrestaShop versions 5.1.1 and before, allows remote attackers to escalate privileges and obtain sensitive information via the method HsAccessoriesGroupProductAbstract::getAcce…
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in InnovaDeluxe "Manufacturer or supplier alphabetical search" (idxrmanufacturer) module for PrestaShop versions 2.0.4 and before, allows remote attackers to escalate privileges and obtain sensitive information via the methods…
- risk 0.64cvss 9.8epss 0.01
Supabase PostgreSQL v15.1 was discovered to contain a SQL injection vulnerability via the component /pg_meta/default/query. NOTE: the vendor's position is that this is an intended feature; also, it exists in the Supabase dashboard product, not the Supabase PostgreSQL product.…
- risk 0.64cvss 9.8epss 0.01
PrestaShop Op'art Easy Redirect >= 1.3.8 and <= 1.3.12 is vulnerable to SQL Injection via Oparteasyredirect::hookActionDispatcher().
- risk 0.64cvss 9.8epss 0.03
The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, limit, and sort parameters to perform SQL injection via /novel/userFeedback/list.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /common/dict/list
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /novel/author/list
- risk 0.64cvss 9.8epss 0.01
jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findInOutMaterialCount() function of jshERP does not filter `column` and `order` parameters well enough, and an attacker can construct malicious payload…
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, limit, and sort parameters to perform SQL injection via /novel/bookContent/list.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL injection via /system/dataPerm/list
- risk 0.64cvss 9.8epss 0.01
Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page.