VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,200)

page 946 of 1,010
  • CVE-2023-37270HigJul 7, 2023
    risk 0.00cvss 7.6epss 0.04

    Piwigo is open source photo gallery software. Prior to version 13.8.0, there is a SQL Injection vulnerability in the login of the administrator screen. The SQL statement that acquires the HTTP Header `User-Agent` is vulnerable at the endpoint that records user information when…

  • CVE-2023-36813HigJul 5, 2023
    risk 0.00cvss 7.1epss 0.01

    Kanboard is project management software that focuses on the Kanban methodology. In versions prior to 1.2.31authenticated user is able to perform a SQL Injection, leading to a privilege escalation or loss of confidentiality. It appears that in some insert and update operations,…

  • CVE-2023-3490CriJun 30, 2023
    risk 0.00cvss 9.8epss 0.01

    SQL Injection in GitHub repository fossbilling/fossbilling prior to 0.5.3.

  • CVE-2023-36663HigJun 25, 2023
    risk 0.00cvss 8.8epss 0.01

    it-novum openITCOCKPIT (aka open IT COCKPIT) 4.6.4 before 4.6.5 allows SQL Injection (by authenticated users) via the sort parameter of the API interface.

  • CVE-2023-35132MedJun 22, 2023
    risk 0.00cvss 6.3epss 0.01

    A limited SQL injection risk was identified on the Mnet SSO access control page. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.

  • CVE-2021-4336MedMay 28, 2023
    risk 0.00cvss 5.5epss 0.01

    A vulnerability was found in ITRS Group monitor-ninja up to 2021.11.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file modules/reports/models/scheduled_reports.php. The manipulation leads to sql injection. Upgrading to version…

  • CVE-2023-2832HigMay 22, 2023
    risk 0.00cvss 7.2epss 0.01

    SQL Injection in GitHub repository unilogies/bumsys prior to 2.2.0.

  • CVE-2023-32308HigMay 15, 2023
    risk 0.00cvss 8.2epss 0.01

    anuko timetracker is an open source time tracking system. Boolean-based blind SQL injection vulnerability existed in Time Tracker invoices.php in versions prior to 1.22.11.5781. This was happening because of a coding error after validating parameters in POST requests. There was…

  • CVE-2023-28839CriApr 18, 2023
    risk 0.00cvss 9.4epss 0.01

    Shoppingfeed PrestaShop is an add-on to the PrestaShop ecommerce platform to synchronize data. The module Shoppingfeed for PrestaShop is vulnerable to SQL injection between version 1.4.0 and 1.8.2 due to a lack of input sanitization. This issue has been addressed in version…

  • CVE-2022-31890CriApr 5, 2023
    risk 0.00cvss 9.8epss 0.01

    SQL Injection vulnerability in audit/class.audit.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb3c6a7789768795ae via the order parameter to the getOrder function.

  • CVE-2023-28843CriMar 31, 2023
    risk 0.00cvss 9.8epss 0.01

    PrestaShop/paypal is an open source module for the PrestaShop web commerce ecosystem which provides paypal payment support. A SQL injection vulnerability found in the PrestaShop paypal module from release from 3.12.0 to and including 3.16.3 allow a remote attacker to gain…

  • CVE-2023-28883CriMar 27, 2023
    risk 0.00cvss 9.8epss 0.01

    In Cerebrate 1.13, a blind SQL injection exists in the searchAll API endpoint.

  • CVE-2023-28424CriMar 20, 2023
    risk 0.00cvss 9.1epss 0.01

    Soko if the code that powers packages.gentoo.org. Prior to version 1.0.2, the two package search handlers, `Search` and `SearchFeed`, implemented in `pkg/app/handler/packages/search.go`, are affected by a SQL injection via the `q` parameter. As a result, unauthenticated…

  • CVE-2023-1495MedMar 19, 2023
    risk 0.00cvss 6.3epss 0.01

    A vulnerability classified as critical was found in Rebuild up to 3.2.3. Affected by this vulnerability is the function queryListOfConfig of the file /admin/robot/approval/list. The manipulation of the argument q leads to sql injection. The attack can be launched remotely. The…

  • CVE-2023-1361MedMar 13, 2023
    risk 0.00cvss 6.5epss 0.01

    SQL Injection in GitHub repository unilogies/bumsys prior to v2.0.2.

  • CVE-2023-26033HigFeb 25, 2023
    risk 0.00cvss 7.5epss 0.01

    Gentoo soko is the code that powers packages.gentoo.org. Versions prior to 1.0.1 are vulnerable to SQL Injection, leading to a Denial of Service. If the user selects (in user preferences) the "Recently Visited Packages" view for the index page, the value of the `search_history`…

  • CVE-2023-24812HigFeb 22, 2023
    risk 0.00cvss 8.8epss 0.01

    Misskey is an open source, decentralized social media platform. In versions prior to 13.3.3 SQL injection is possible due to insufficient parameter validation in the note search API by tag (notes/search-by-tag). This has been fixed in version 13.3.3. Users are advised to…

  • CVE-2023-26093CriFeb 20, 2023
    risk 0.00cvss 9.8epss 0.01

    Liima before 1.17.28 allows Hibernate query language (HQL) injection, related to colToSort in the deployment filter.

  • CVE-2022-45962MedFeb 13, 2023
    risk 0.00cvss 6.5epss 0.01

    Open Solutions for Education, Inc openSIS Community Edition v8.0 and earlier is vulnerable to SQL Injection via CalendarModal.php.

  • CVE-2023-0771HigFeb 10, 2023
    risk 0.00cvss 8.8epss 0.01

    SQL Injection in GitHub repository ampache/ampache prior to 5.5.7,develop.