VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 76 of 1,043
  • CVE-2024-23763CriFeb 12, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Gambio through 4.9.2.0 allows attackers to run arbitrary SQL commands via crafted GET request using modifiers[attribute][] parameter.

  • CVE-2024-25316CriFeb 9, 2024
    risk 0.64cvss 9.8epss 0.01

    Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'eid' parameter in Hotel/admin/usersettingdel.php?eid=2.

  • CVE-2024-25315CriFeb 9, 2024
    risk 0.64cvss 9.8epss 0.01

    Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'rid' parameter in Hotel/admin/roombook.php?rid=2.

  • CVE-2024-25314CriFeb 9, 2024
    risk 0.64cvss 9.8epss 0.01

    Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'sid' parameter in Hotel/admin/show.php?sid=2.

  • CVE-2024-25307CriFeb 9, 2024
    risk 0.64cvss 9.8epss 0.01

    Code-projects Cinema Seat Reservation System 1.0 allows SQL Injection via the 'id' parameter at "/Cinema-Reservation/booking.php?id=1."

  • CVE-2024-25302CriFeb 9, 2024
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester Event Student Attendance System 1.0, allows SQL Injection via the 'student' parameter.

  • CVE-2023-6677CriFeb 9, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oduyo Financial Technology Online Collection allows SQL Injection. This issue affects Online Collection: before v.1.0.2.

  • CVE-2024-24308CriFeb 9, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Boostmyshop (boostmyshopagent) module for Prestashop versions 1.1.9 and before, allows remote attackers to escalate privileges and obtain sensitive information via changeOrderCarrier.php, relayPoint.php, and shippingConfirmation.php.

  • CVE-2023-50026CriFeb 9, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Presta Monster "Multi Accessories Pro" (hsmultiaccessoriespro) module for PrestaShop versions 5.1.1 and before, allows remote attackers to escalate privileges and obtain sensitive information via the method HsAccessoriesGroupProductAbstract::getAcce…

  • CVE-2023-46350CriFeb 9, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in InnovaDeluxe "Manufacturer or supplier alphabetical search" (idxrmanufacturer) module for PrestaShop versions 2.0.4 and before, allows remote attackers to escalate privileges and obtain sensitive information via the methods…

  • CVE-2024-24213CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    Supabase PostgreSQL v15.1 was discovered to contain a SQL injection vulnerability via the component /pg_meta/default/query. NOTE: the vendor's position is that this is an intended feature; also, it exists in the Supabase dashboard product, not the Supabase PostgreSQL product.…

  • CVE-2023-50061CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    PrestaShop Op'art Easy Redirect >= 1.3.8 and <= 1.3.12 is vulnerable to SQL Injection via Oparteasyredirect::hookActionDispatcher().

  • CVE-2024-1207CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.03

    The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…

  • CVE-2024-24021CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, limit, and sort parameters to perform SQL injection via /novel/userFeedback/list.

  • CVE-2024-24017CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /common/dict/list

  • CVE-2024-24014CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /novel/author/list

  • CVE-2024-24003CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findInOutMaterialCount() function of jshERP does not filter `column` and `order` parameters well enough, and an attacker can construct malicious payload…

  • CVE-2024-24023CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, limit, and sort parameters to perform SQL injection via /novel/bookContent/list.

  • CVE-2024-24018CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL injection via /system/dataPerm/list

  • CVE-2024-24133CriFeb 7, 2024
    risk 0.64cvss 9.8epss 0.01

    Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page.