CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 88 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-39649 | Cri | 0.64 | 9.8 | 0.01 | Oct 3, 2023 | Improper neutralization of SQL parameter in Theme Volty CMS Category Slider module for PrestaShop. In the module “Theme Volty CMS Category Slider” (tvcmscategoryslider) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected… | ||
| CVE-2023-39648 | Cri | 0.64 | 9.8 | 0.01 | Oct 3, 2023 | Improper neutralization of SQL parameter in Theme Volty CMS Testimonial module for PrestaShop. In the module “Theme Volty CMS Testimonial” (tvcmstestimonial) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions. | ||
| CVE-2023-39646 | Cri | 0.64 | 9.8 | 0.01 | Oct 3, 2023 | Improper neutralization of SQL parameter in Theme Volty CMS Category Chain Slider module for PrestaShop. In the module “Theme Volty CMS Category Chain Slide"(tvcmscategorychainslider) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in… | ||
| CVE-2023-39645 | Cri | 0.64 | 9.8 | 0.01 | Oct 3, 2023 | Improper neutralization of SQL parameter in Theme Volty CMS Payment Icon module for PrestaShop. In the module “Theme Volty CMS Payment Icon” (tvcmspaymenticon) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions. | ||
| CVE-2023-43980 | Cri | 0.64 | 9.8 | 0.01 | Oct 2, 2023 | Presto Changeo testsitecreator up to v1.1.1 was discovered to contain a SQL injection vulnerability via the component disable_json.php. | ||
| CVE-2023-44166 | Cri | 0.64 | 9.8 | 0.01 | Sep 28, 2023 | The 'age' parameter of the process_registration.php resource does not validate the characters received and they are sent unfiltered to the database. | ||
| CVE-2023-44164 | Cri | 0.64 | 9.8 | 0.01 | Sep 28, 2023 | The 'Email' parameter of the process_login.php resource does not validate the characters received and they are sent unfiltered to the database. | ||
| CVE-2023-44163 | Cri | 0.64 | 9.8 | 0.01 | Sep 28, 2023 | The 'search' parameter of the process_search.php resource does not validate the characters received and they are sent unfiltered to the database. | ||
| CVE-2023-43739 | Cri | 0.64 | 9.8 | 0.01 | Sep 28, 2023 | The 'bookisbn' parameter of the cart.php resource does not validate the characters received and they are sent unfiltered to the database. | ||
| CVE-2023-5053 | Cri | 0.64 | 9.8 | 0.01 | Sep 28, 2023 | Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is vulnerable to SQLI. | ||
| CVE-2023-5004 | Cri | 0.64 | 9.8 | 0.01 | Sep 28, 2023 | Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is vulnerable to SQLI. | ||
| CVE-2023-43013 | Cri | 0.64 | 9.8 | 0.01 | Sep 28, 2023 | Asset Management System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'email' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control. | ||
| CVE-2023-30415 | Cri | 0.64 | 9.8 | 0.01 | Sep 28, 2023 | Sourcecodester Packers and Movers Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /inquiries/view_inquiry.php. | ||
| CVE-2023-38870 | Cri | 0.64 | 9.8 | 0.01 | Sep 28, 2023 | A SQL injection vulnerability exists in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1. The cash book has a feature to list accomplishments by category, and the 'category_id' parameter is vulnerable to SQL Injection. | ||
| CVE-2023-4737 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hedef Tracking Admin Panel allows SQL Injection. This issue affects Admin Panel: before 1.2. | ||
| CVE-2023-35071 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MRV Tech Logging Administration Panel allows SQL Injection. This issue affects Logging Administration Panel: before 20230915 . | ||
| CVE-2023-39640 | Cri | 0.64 | 9.8 | 0.01 | Sep 25, 2023 | UpLight cookiebanner before 1.5.1 was discovered to contain a SQL injection vulnerability via the component Hook::getHookModuleExecList(). | ||
| CVE-2023-43470 | Cri | 0.64 | 9.8 | 0.01 | Sep 23, 2023 | SQL injection vulnerability in janobe Online Voting System v.1.0 allows a remote attacker to execute arbitrary code via the checklogin.php component. | ||
| CVE-2023-43469 | Cri | 0.64 | 9.8 | 0.01 | Sep 23, 2023 | SQL injection vulnerability in janobe Online Job Portal v.2020 allows a remote attacker to execute arbitrary code via the ForPass.php component. | ||
| CVE-2023-43468 | Cri | 0.64 | 9.8 | 0.01 | Sep 23, 2023 | SQL injection vulnerability in janobe Online Job Portal v.2020 allows a remote attacker to execute arbitrary code via the login.php component. |
- risk 0.64cvss 9.8epss 0.01
Improper neutralization of SQL parameter in Theme Volty CMS Category Slider module for PrestaShop. In the module “Theme Volty CMS Category Slider” (tvcmscategoryslider) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected…
- risk 0.64cvss 9.8epss 0.01
Improper neutralization of SQL parameter in Theme Volty CMS Testimonial module for PrestaShop. In the module “Theme Volty CMS Testimonial” (tvcmstestimonial) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions.
- risk 0.64cvss 9.8epss 0.01
Improper neutralization of SQL parameter in Theme Volty CMS Category Chain Slider module for PrestaShop. In the module “Theme Volty CMS Category Chain Slide"(tvcmscategorychainslider) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in…
- risk 0.64cvss 9.8epss 0.01
Improper neutralization of SQL parameter in Theme Volty CMS Payment Icon module for PrestaShop. In the module “Theme Volty CMS Payment Icon” (tvcmspaymenticon) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions.
- risk 0.64cvss 9.8epss 0.01
Presto Changeo testsitecreator up to v1.1.1 was discovered to contain a SQL injection vulnerability via the component disable_json.php.
- risk 0.64cvss 9.8epss 0.01
The 'age' parameter of the process_registration.php resource does not validate the characters received and they are sent unfiltered to the database.
- risk 0.64cvss 9.8epss 0.01
The 'Email' parameter of the process_login.php resource does not validate the characters received and they are sent unfiltered to the database.
- risk 0.64cvss 9.8epss 0.01
The 'search' parameter of the process_search.php resource does not validate the characters received and they are sent unfiltered to the database.
- risk 0.64cvss 9.8epss 0.01
The 'bookisbn' parameter of the cart.php resource does not validate the characters received and they are sent unfiltered to the database.
- risk 0.64cvss 9.8epss 0.01
Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is vulnerable to SQLI.
- risk 0.64cvss 9.8epss 0.01
Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is vulnerable to SQLI.
- risk 0.64cvss 9.8epss 0.01
Asset Management System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'email' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Packers and Movers Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /inquiries/view_inquiry.php.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability exists in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1. The cash book has a feature to list accomplishments by category, and the 'category_id' parameter is vulnerable to SQL Injection.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hedef Tracking Admin Panel allows SQL Injection. This issue affects Admin Panel: before 1.2.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MRV Tech Logging Administration Panel allows SQL Injection. This issue affects Logging Administration Panel: before 20230915 .
- risk 0.64cvss 9.8epss 0.01
UpLight cookiebanner before 1.5.1 was discovered to contain a SQL injection vulnerability via the component Hook::getHookModuleExecList().
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in janobe Online Voting System v.1.0 allows a remote attacker to execute arbitrary code via the checklogin.php component.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in janobe Online Job Portal v.2020 allows a remote attacker to execute arbitrary code via the ForPass.php component.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in janobe Online Job Portal v.2020 allows a remote attacker to execute arbitrary code via the login.php component.