VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,855)

page 91 of 1,043
  • CVE-2023-39654CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    abupy up to v0.4.0 was discovered to contain a SQL injection vulnerability via the component abupy.MarketBu.ABuSymbol.search_to_symbol_dict.

  • CVE-2023-4531CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mestav Software E-commerce Software allows SQL Injection. This issue affects E-commerce Software: before 20230901 .

  • CVE-2023-4034CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digita Information Technology Smartrise Document Management System allows SQL Injection. This issue affects Smartrise Document Management System: before Hvl-2.0.

  • CVE-2023-3616CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mava Software Hotel Management System allows SQL Injection. This issue affects Hotel Management System: before 2.0.

  • CVE-2023-35072CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Coyav Travel Proagent allows SQL Injection. This issue affects Proagent: before 20230904 .

  • CVE-2023-35068CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BMA Personnel Tracking System allows SQL Injection. This issue affects Personnel Tracking System: before 20230904.

  • CVE-2023-35065CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Osoft Paint Production Management allows SQL Injection. This issue affects Paint Production Management: before 2.1.

  • CVE-2023-36361CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Audimexee v14.1.7 was discovered to contain a SQL injection vulnerability via the p_table_name parameter.

  • CVE-2023-36076CriSep 1, 2023
    risk 0.64cvss 9.8epss 0.03

    SQL Injection vulnerability in smanga version 3.1.9 and earlier, allows remote attackers to execute arbitrary code and gain sensitive information via mediaId, mangaId, and userId parameters in php/history/add.php.

  • CVE-2023-41364CriSep 1, 2023
    risk 0.64cvss 9.8epss 0.01

    In tine through 2023.01.14.325, the sort parameter of the /index.php endpoint allows SQL Injection.

  • CVE-2023-41636CriAug 31, 2023
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in the Data Richiesta dal parameter of GruppoSCAI RealGimm v1.1.37p38 allows attackers to access the database and execute arbitrary commands via a crafted SQL query.

  • CVE-2021-3262CriAug 29, 2023
    risk 0.64cvss 9.8epss 0.01

    TripSpark VEO Transportation-2.2.x-XP_BB-20201123-184084 NovusEDU-2.2.x-XP_BB-20201123-184084 allows unsafe data inputs in POST body parameters from end users without sanitizing using server-side logic. It was possible to inject custom SQL commands into the "Student Busing…

  • CVE-2023-39650CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.04

    Theme Volty CMS Blog up to version v4.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /tvcmsblog/single.

  • CVE-2023-39652CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    theme volty tvcmsvideotab up to v4.0.0 was discovered to contain a SQL injection vulnerability via the component TvcmsVideoTabConfirmDeleteModuleFrontController::run().

  • CVE-2023-39560CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.05

    ECTouch v2 was discovered to contain a SQL injection vulnerability via the $arr['id'] parameter at \default\helpers\insert.php.

  • CVE-2023-40749CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.04

    PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php.

  • CVE-2023-40748CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.03

    PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php.

  • CVE-2023-39807CriAug 21, 2023
    risk 0.64cvss 9.8epss 0.01

    N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a SQL injection vulnerability via the a_passwd parameter at /portal/user-register.php.

  • CVE-2023-33663CriAug 16, 2023
    risk 0.64cvss 9.8epss 0.01

    In the module “Customization fields fee for your store” (aicustomfee) from ai-dev module for PrestaShop, an attacker can perform SQL injection up to 0.2.0. Release 0.2.1 fixed this security issue.

  • CVE-2023-39851CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    webchess v1.0 was discovered to contain a SQL injection vulnerability via the $playerID parameter at mainmenu.php. NOTE: this is disputed by a third party who indicates that the playerID is a session variable controlled by the server, and thus cannot be used for exploitation.