VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,812)

page 9 of 1,041
  • CVE-2024-50330CriNov 12, 2024
    risk 0.67cvss 9.8epss 0.40

    SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated attacker to achieve remote code execution.

  • CVE-2024-48307CriOct 31, 2024
    risk 0.67cvss 9.8epss 0.44

    JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData.

  • CVE-2024-48573CriOct 29, 2024
    risk 0.67cvss 9.8epss 0.01

    A NoSQL injection vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to reset user and administrator account passwords via the "Reset password" feature.

  • CVE-2024-44541CriSep 11, 2024
    risk 0.67cvss 9.8epss 0.03

    evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action=processlogin."

  • CVE-2024-45622CriSep 2, 2024
    risk 0.67cvss 9.8epss 0.37

    ASIS (aka Aplikasi Sistem Sekolah using CodeIgniter 3) 3.0.0 through 3.2.0 allows index.php username SQL injection for Authentication Bypass.

  • CVE-2024-38289CriJul 25, 2024
    risk 0.67cvss 9.8epss 0.41

    A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to extract hashed passwords from the database, and authenticate to the application, via crafted SQL input.

  • CVE-2024-28595CriMar 19, 2024
    risk 0.67cvss 9.8epss 0.01

    SQL Injection vulnerability in Employee Management System v1.0 allows attackers to run arbitrary SQL commands via the admin_id parameter in update-admin.php.

  • CVE-2024-24401CriFeb 26, 2024
    risk 0.67cvss 9.8epss 0.46

    SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.php component.

  • CVE-2024-24495CriFeb 8, 2024
    risk 0.67cvss 9.8epss 0.01

    SQL Injection vulnerability in delete-tracker.php in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via crafted GET request.

  • CVE-2023-49085HigDec 22, 2023
    risk 0.67cvss 8.8epss 0.74

    Cacti provides an operational monitoring and fault management framework. In versions 1.2.25 and prior, it is possible to execute arbitrary SQL code through the `pollers.php` script. An authorized user may be able to execute arbitrary SQL code. The vulnerable component is the…

  • CVE-2023-34635CriJul 31, 2023
    risk 0.67cvss 9.8epss 0.04

    Wifi Soft Unibox Administration 3.0 and 3.1 is vulnerable to SQL Injection. The vulnerability occurs because of not validating or sanitizing the user input in the username field of the login page.

  • CVE-2023-36934CriJul 5, 2023
    risk 0.67cvss 9.1epss 0.95

    In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated…

  • CVE-2023-33592CriJun 28, 2023
    risk 0.67cvss 9.8epss 0.04

    Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=system_info/contact_information.

  • CVE-2023-34581CriJun 12, 2023
    risk 0.67cvss 9.8epss 0.03

    Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/?page=services/view&id=2

  • CVE-2023-33362CriMay 23, 2023
    risk 0.67cvss 9.8epss 0.09

    Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function.

  • CVE-2023-1934CriMay 12, 2023
    risk 0.67cvss 9.8epss 0.08

    The PnPSCADA system, a product of SDG Technologies CC, is afflicted by a critical unauthenticated error-based PostgreSQL Injection vulnerability. Present within the hitlogcsv.jsp endpoint, this security flaw permits unauthenticated attackers to engage with the underlying…

  • CVE-2023-1730CriMay 2, 2023
    risk 0.67cvss 9.8epss 0.41

    The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks

  • CVE-2023-28662CriMar 22, 2023
    risk 0.67cvss 9.8epss 0.42

    The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by an unauthenticated SQL injection vulnerability in the template parameter in the wpgv_doajax_voucher_pdf_save_func action.

  • CVE-2023-23156CriFeb 27, 2023
    risk 0.67cvss 9.8epss 0.04

    Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid parameter in the single-product page.

  • CVE-2022-40347CriFeb 17, 2023
    risk 0.67cvss 9.8epss 0.05

    SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType' and 'name' parameters, allows attackers to execute arbitrary code and gain sensitive information.