VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,387)

page 764 of 1,020
  • CVE-2023-44284MedDec 14, 2023
    risk 0.28cvss 4.3epss 0.01

    Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an SQL Injection vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the…

  • CVE-2023-25651MedDec 14, 2023
    risk 0.28cvss 4.3epss 0.00

    There is a SQL injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of SMS interface parameter, an authenticated attacker could use the vulnerability to execute SQL injection and cause information leak.

  • CVE-2023-36652MedDec 12, 2023
    risk 0.28cvss 4.3epss 0.01

    A SQL Injection in the users searching REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to read database data via SQL commands injected in the search parameter.

  • CVE-2023-34626MedJun 15, 2023
    risk 0.28cvss 4.3epss 0.01

    Piwigo 13.7.0 is vulnerable to SQL Injection via the "Users" function.

  • CVE-2023-30465MedApr 11, 2023
    risk 0.28cvss 5.3epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.5.0. By manipulating the "orderType" parameter and the ordering of the returned…

  • CVE-2023-1741MedMar 30, 2023
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in jeecg-boot 3.5.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file SysDictMapper.java of the component Sleep Command Handler. The manipulation leads to sql injection. The attack can be…

  • CVE-2023-25196MedMar 28, 2023
    risk 0.28cvss 4.3epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache Fineract. Authorized users may be able to change or add data in certain components.   This issue affects Apache Fineract: from 1.4 through…

  • CVE-2023-22630MedJan 23, 2023
    risk 0.28cvss 4.3epss 0.01

    IzyBat Orange casiers before 20221102_1 allows SQL Injection via a getCasier.php?taille= URI.

  • CVE-2022-43860MedDec 24, 2022
    risk 0.28cvss 4.3epss 0.00

    IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information they are authorized to but not while using this interface. By performing an SQL injection an attacker could see user profile attributes through this interface. IBM X-Force…

  • CVE-2022-3711MedDec 1, 2022
    risk 0.28cvss 4.3epss 0.01

    A post-auth read-only SQL injection vulnerability allows users to read non-sensitive configuration database contents in the User Portal of Sophos Firewall releases older than version 19.5 GA.

  • CVE-2022-25223MedMar 23, 2022
    risk 0.28cvss 4.3epss 0.01

    Money Transfer Management System Version 1.0 allows an authenticated user to inject SQL queries in 'mtms/admin/?page=transaction/view_details' via the 'id' parameter.

  • CVE-2021-33688MedSep 14, 2021
    risk 0.28cvss 4.3epss 0.01

    SAP Business One allows an attacker with business privileges to execute crafted database queries, exposing the back-end database. Due to framework restrictions, only some information can be obtained.

  • CVE-2021-31818MedJun 17, 2021
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API because user supplied data in the API request isn’t parameterised correctly. Exploiting this vulnerability could allow unauthorised access to database tables.

  • CVE-2020-15792MedOct 15, 2020
    risk 0.28cvss 4.3epss 0.01

    A vulnerability has been identified in Desigo Insight (All versions). The web service does not properly apply input validation for some query parameters in a reserved area. This could allow an authenticated attacker to retrieve data via a content-based blind SQL injection attack.

  • CVE-2020-24569MedSep 30, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a blind SQL injection in the knximport component via an advanced attack vector, allowing logged in attackers to discover arbitrary information.

  • CVE-2020-5920MedAug 26, 2020
    risk 0.28cvss 4.3epss 0.01

    In versions 15.0.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, a vulnerability in the BIG-IP AFM Configuration utility may allow any authenticated BIG-IP user to perform a read-only blind SQL injection attack.

  • CVE-2020-3378MedJul 16, 2020
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in the web-based management interface for Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to impact the integrity of an affected system by executing arbitrary SQL queries. The vulnerability is due to insufficient validation of…

  • CVE-2020-11437MedJul 15, 2020
    risk 0.28cvss 4.3epss 0.01

    LibreHealth EMR v2.0.0 is affected by SQL injection allowing low-privilege authenticated users to enumerate the database.

  • CVE-2019-0393MedNov 13, 2019
    risk 0.28cvss 4.3epss 0.01

    An SQL Injection vulnerability in SAP Quality Management (corrected in S4CORE versions 1.0, 1.01, 1.02, 1.03) allows an attacker to carry out targeted database queries that can read individual fields of historical inspection results.

  • CVE-2019-6658MedNov 1, 2019
    risk 0.28cvss 4.3epss 0.01

    On BIG-IP AFM 15.0.0-15.0.1, 14.0.0-14.1.2, 13.1.0-13.1.3.1, and 12.1.0-12.1.5, a vulnerability in the AFM configuration utility may allow any authenticated BIG-IP user to run an SQL injection attack.