CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,200)
page 946 of 1,010| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-37270 | Hig | 0.00 | 7.6 | 0.04 | Jul 7, 2023 | Piwigo is open source photo gallery software. Prior to version 13.8.0, there is a SQL Injection vulnerability in the login of the administrator screen. The SQL statement that acquires the HTTP Header `User-Agent` is vulnerable at the endpoint that records user information when… | ||
| CVE-2023-36813 | Hig | 0.00 | 7.1 | 0.01 | Jul 5, 2023 | Kanboard is project management software that focuses on the Kanban methodology. In versions prior to 1.2.31authenticated user is able to perform a SQL Injection, leading to a privilege escalation or loss of confidentiality. It appears that in some insert and update operations,… | ||
| CVE-2023-3490 | Cri | 0.00 | 9.8 | 0.01 | Jun 30, 2023 | SQL Injection in GitHub repository fossbilling/fossbilling prior to 0.5.3. | ||
| CVE-2023-36663 | Hig | 0.00 | 8.8 | 0.01 | Jun 25, 2023 | it-novum openITCOCKPIT (aka open IT COCKPIT) 4.6.4 before 4.6.5 allows SQL Injection (by authenticated users) via the sort parameter of the API interface. | ||
| CVE-2023-35132 | Med | 0.00 | 6.3 | 0.01 | Jun 22, 2023 | A limited SQL injection risk was identified on the Mnet SSO access control page. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions. | ||
| CVE-2021-4336 | Med | 0.00 | 5.5 | 0.01 | May 28, 2023 | A vulnerability was found in ITRS Group monitor-ninja up to 2021.11.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file modules/reports/models/scheduled_reports.php. The manipulation leads to sql injection. Upgrading to version… | ||
| CVE-2023-2832 | Hig | 0.00 | 7.2 | 0.01 | May 22, 2023 | SQL Injection in GitHub repository unilogies/bumsys prior to 2.2.0. | ||
| CVE-2023-32308 | Hig | 0.00 | 8.2 | 0.01 | May 15, 2023 | anuko timetracker is an open source time tracking system. Boolean-based blind SQL injection vulnerability existed in Time Tracker invoices.php in versions prior to 1.22.11.5781. This was happening because of a coding error after validating parameters in POST requests. There was… | ||
| CVE-2023-28839 | Cri | 0.00 | 9.4 | 0.01 | Apr 18, 2023 | Shoppingfeed PrestaShop is an add-on to the PrestaShop ecommerce platform to synchronize data. The module Shoppingfeed for PrestaShop is vulnerable to SQL injection between version 1.4.0 and 1.8.2 due to a lack of input sanitization. This issue has been addressed in version… | ||
| CVE-2022-31890 | Cri | 0.00 | 9.8 | 0.01 | Apr 5, 2023 | SQL Injection vulnerability in audit/class.audit.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb3c6a7789768795ae via the order parameter to the getOrder function. | ||
| CVE-2023-28843 | Cri | 0.00 | 9.8 | 0.01 | Mar 31, 2023 | PrestaShop/paypal is an open source module for the PrestaShop web commerce ecosystem which provides paypal payment support. A SQL injection vulnerability found in the PrestaShop paypal module from release from 3.12.0 to and including 3.16.3 allow a remote attacker to gain… | ||
| CVE-2023-28883 | Cri | 0.00 | 9.8 | 0.01 | Mar 27, 2023 | In Cerebrate 1.13, a blind SQL injection exists in the searchAll API endpoint. | ||
| CVE-2023-28424 | Cri | 0.00 | 9.1 | 0.01 | Mar 20, 2023 | Soko if the code that powers packages.gentoo.org. Prior to version 1.0.2, the two package search handlers, `Search` and `SearchFeed`, implemented in `pkg/app/handler/packages/search.go`, are affected by a SQL injection via the `q` parameter. As a result, unauthenticated… | ||
| CVE-2023-1495 | Med | 0.00 | 6.3 | 0.01 | Mar 19, 2023 | A vulnerability classified as critical was found in Rebuild up to 3.2.3. Affected by this vulnerability is the function queryListOfConfig of the file /admin/robot/approval/list. The manipulation of the argument q leads to sql injection. The attack can be launched remotely. The… | ||
| CVE-2023-1361 | Med | 0.00 | 6.5 | 0.01 | Mar 13, 2023 | SQL Injection in GitHub repository unilogies/bumsys prior to v2.0.2. | ||
| CVE-2023-26033 | Hig | 0.00 | 7.5 | 0.01 | Feb 25, 2023 | Gentoo soko is the code that powers packages.gentoo.org. Versions prior to 1.0.1 are vulnerable to SQL Injection, leading to a Denial of Service. If the user selects (in user preferences) the "Recently Visited Packages" view for the index page, the value of the `search_history`… | ||
| CVE-2023-24812 | Hig | 0.00 | 8.8 | 0.01 | Feb 22, 2023 | Misskey is an open source, decentralized social media platform. In versions prior to 13.3.3 SQL injection is possible due to insufficient parameter validation in the note search API by tag (notes/search-by-tag). This has been fixed in version 13.3.3. Users are advised to… | ||
| CVE-2023-26093 | Cri | 0.00 | 9.8 | 0.01 | Feb 20, 2023 | Liima before 1.17.28 allows Hibernate query language (HQL) injection, related to colToSort in the deployment filter. | ||
| CVE-2022-45962 | Med | 0.00 | 6.5 | 0.01 | Feb 13, 2023 | Open Solutions for Education, Inc openSIS Community Edition v8.0 and earlier is vulnerable to SQL Injection via CalendarModal.php. | ||
| CVE-2023-0771 | Hig | 0.00 | 8.8 | 0.01 | Feb 10, 2023 | SQL Injection in GitHub repository ampache/ampache prior to 5.5.7,develop. |
- risk 0.00cvss 7.6epss 0.04
Piwigo is open source photo gallery software. Prior to version 13.8.0, there is a SQL Injection vulnerability in the login of the administrator screen. The SQL statement that acquires the HTTP Header `User-Agent` is vulnerable at the endpoint that records user information when…
- risk 0.00cvss 7.1epss 0.01
Kanboard is project management software that focuses on the Kanban methodology. In versions prior to 1.2.31authenticated user is able to perform a SQL Injection, leading to a privilege escalation or loss of confidentiality. It appears that in some insert and update operations,…
- risk 0.00cvss 9.8epss 0.01
SQL Injection in GitHub repository fossbilling/fossbilling prior to 0.5.3.
- risk 0.00cvss 8.8epss 0.01
it-novum openITCOCKPIT (aka open IT COCKPIT) 4.6.4 before 4.6.5 allows SQL Injection (by authenticated users) via the sort parameter of the API interface.
- risk 0.00cvss 6.3epss 0.01
A limited SQL injection risk was identified on the Mnet SSO access control page. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.
- risk 0.00cvss 5.5epss 0.01
A vulnerability was found in ITRS Group monitor-ninja up to 2021.11.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file modules/reports/models/scheduled_reports.php. The manipulation leads to sql injection. Upgrading to version…
- risk 0.00cvss 7.2epss 0.01
SQL Injection in GitHub repository unilogies/bumsys prior to 2.2.0.
- risk 0.00cvss 8.2epss 0.01
anuko timetracker is an open source time tracking system. Boolean-based blind SQL injection vulnerability existed in Time Tracker invoices.php in versions prior to 1.22.11.5781. This was happening because of a coding error after validating parameters in POST requests. There was…
- risk 0.00cvss 9.4epss 0.01
Shoppingfeed PrestaShop is an add-on to the PrestaShop ecommerce platform to synchronize data. The module Shoppingfeed for PrestaShop is vulnerable to SQL injection between version 1.4.0 and 1.8.2 due to a lack of input sanitization. This issue has been addressed in version…
- risk 0.00cvss 9.8epss 0.01
SQL Injection vulnerability in audit/class.audit.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb3c6a7789768795ae via the order parameter to the getOrder function.
- risk 0.00cvss 9.8epss 0.01
PrestaShop/paypal is an open source module for the PrestaShop web commerce ecosystem which provides paypal payment support. A SQL injection vulnerability found in the PrestaShop paypal module from release from 3.12.0 to and including 3.16.3 allow a remote attacker to gain…
- risk 0.00cvss 9.8epss 0.01
In Cerebrate 1.13, a blind SQL injection exists in the searchAll API endpoint.
- risk 0.00cvss 9.1epss 0.01
Soko if the code that powers packages.gentoo.org. Prior to version 1.0.2, the two package search handlers, `Search` and `SearchFeed`, implemented in `pkg/app/handler/packages/search.go`, are affected by a SQL injection via the `q` parameter. As a result, unauthenticated…
- risk 0.00cvss 6.3epss 0.01
A vulnerability classified as critical was found in Rebuild up to 3.2.3. Affected by this vulnerability is the function queryListOfConfig of the file /admin/robot/approval/list. The manipulation of the argument q leads to sql injection. The attack can be launched remotely. The…
- risk 0.00cvss 6.5epss 0.01
SQL Injection in GitHub repository unilogies/bumsys prior to v2.0.2.
- risk 0.00cvss 7.5epss 0.01
Gentoo soko is the code that powers packages.gentoo.org. Versions prior to 1.0.1 are vulnerable to SQL Injection, leading to a Denial of Service. If the user selects (in user preferences) the "Recently Visited Packages" view for the index page, the value of the `search_history`…
- risk 0.00cvss 8.8epss 0.01
Misskey is an open source, decentralized social media platform. In versions prior to 13.3.3 SQL injection is possible due to insufficient parameter validation in the note search API by tag (notes/search-by-tag). This has been fixed in version 13.3.3. Users are advised to…
- risk 0.00cvss 9.8epss 0.01
Liima before 1.17.28 allows Hibernate query language (HQL) injection, related to colToSort in the deployment filter.
- risk 0.00cvss 6.5epss 0.01
Open Solutions for Education, Inc openSIS Community Edition v8.0 and earlier is vulnerable to SQL Injection via CalendarModal.php.
- risk 0.00cvss 8.8epss 0.01
SQL Injection in GitHub repository ampache/ampache prior to 5.5.7,develop.