VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 88 of 1,043
  • CVE-2023-39649CriOct 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper neutralization of SQL parameter in Theme Volty CMS Category Slider module for PrestaShop. In the module “Theme Volty CMS Category Slider” (tvcmscategoryslider) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected…

  • CVE-2023-39648CriOct 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper neutralization of SQL parameter in Theme Volty CMS Testimonial module for PrestaShop. In the module “Theme Volty CMS Testimonial” (tvcmstestimonial) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions.

  • CVE-2023-39646CriOct 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper neutralization of SQL parameter in Theme Volty CMS Category Chain Slider module for PrestaShop. In the module “Theme Volty CMS Category Chain Slide"(tvcmscategorychainslider) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in…

  • CVE-2023-39645CriOct 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper neutralization of SQL parameter in Theme Volty CMS Payment Icon module for PrestaShop. In the module “Theme Volty CMS Payment Icon” (tvcmspaymenticon) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions.

  • CVE-2023-43980CriOct 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Presto Changeo testsitecreator up to v1.1.1 was discovered to contain a SQL injection vulnerability via the component disable_json.php.

  • CVE-2023-44166CriSep 28, 2023
    risk 0.64cvss 9.8epss 0.01

    The 'age' parameter of the process_registration.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-44164CriSep 28, 2023
    risk 0.64cvss 9.8epss 0.01

    The 'Email' parameter of the process_login.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-44163CriSep 28, 2023
    risk 0.64cvss 9.8epss 0.01

    The 'search' parameter of the process_search.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-43739CriSep 28, 2023
    risk 0.64cvss 9.8epss 0.01

    The 'bookisbn' parameter of the cart.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-5053CriSep 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is vulnerable to SQLI.

  • CVE-2023-5004CriSep 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is vulnerable to SQLI.

  • CVE-2023-43013CriSep 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Asset Management System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'email' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control.

  • CVE-2023-30415CriSep 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester Packers and Movers Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /inquiries/view_inquiry.php.

  • CVE-2023-38870CriSep 28, 2023
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1. The cash book has a feature to list accomplishments by category, and the 'category_id' parameter is vulnerable to SQL Injection.

  • CVE-2023-4737CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hedef Tracking Admin Panel allows SQL Injection. This issue affects Admin Panel: before 1.2.

  • CVE-2023-35071CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MRV Tech Logging Administration Panel allows SQL Injection. This issue affects Logging Administration Panel: before 20230915 .

  • CVE-2023-39640CriSep 25, 2023
    risk 0.64cvss 9.8epss 0.01

    UpLight cookiebanner before 1.5.1 was discovered to contain a SQL injection vulnerability via the component Hook::getHookModuleExecList().

  • CVE-2023-43470CriSep 23, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in janobe Online Voting System v.1.0 allows a remote attacker to execute arbitrary code via the checklogin.php component.

  • CVE-2023-43469CriSep 23, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in janobe Online Job Portal v.2020 allows a remote attacker to execute arbitrary code via the ForPass.php component.

  • CVE-2023-43468CriSep 23, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in janobe Online Job Portal v.2020 allows a remote attacker to execute arbitrary code via the login.php component.