VYPR

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7

CVEs mapped to this weakness (20,200)

page 949 of 1,010
  • CVE-2022-0754MedMar 7, 2022
    risk 0.00cvss 6.5epss 0.01

    SQL Injection in GitHub repository salesagility/suitecrm prior to 7.12.5.

  • CVE-2021-23214HigMar 4, 2022
    risk 0.00cvss 8.1epss 0.02

    When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and…

  • CVE-2022-21720MedJan 28, 2022
    risk 0.00cvss 4.9epss 0.01

    GLPI is a free asset and IT management software package. Prior to version 9.5.7, an entity administrator is capable of retrieving normally inaccessible data via SQL injection. Version 9.5.7 contains a patch for this issue. As a workaround, disabling the `Entities` update right…

  • CVE-2021-43863HigJan 25, 2022
    risk 0.00cvss 7.5epss 0.02

    The Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. The Nextcloud Android app uses content providers to manage its data. Prior to version 3.18.1, the providers `FileContentProvider` and `DiskLruImageCacheFileProvider` have security…

  • CVE-2022-21666HigJan 10, 2022
    risk 0.00cvss 7.2epss 0.01

    Useful Simple Open-Source CMS (USOC) is a content management system (CMS) for programmers. Versions prior to Pb2.4Bfx3 allowed Sql injection in usersearch.php only for users with administrative privileges. Users should replace the file `admin/pages/useredit.php` with a newer…

  • CVE-2021-36774MedJan 6, 2022
    risk 0.00cvss 6.5epss 0.02

    Apache Kylin allows users to read data from other database systems using JDBC. The MySQL JDBC driver supports certain properties, which, if left unmitigated, can allow an attacker to execute arbitrary code from a hacker-controlled malicious MySQL server within Kylin server…

  • CVE-2022-21644CriJan 4, 2022
    risk 0.00cvss 9.1epss 0.01

    USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via usersearch.php. In search terms provided by the user were not sanitized and were used directly to construct a sql statement. The only users permitted to search are site…

  • CVE-2022-21643CriJan 4, 2022
    risk 0.00cvss 10.0epss 0.01

    USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via register.php. In particular usernames, email addresses, and passwords provided by the user were not sanitized and were used directly to construct a sql statement. Users…

  • CVE-2021-43851HigDec 22, 2021
    risk 0.00cvss 8.1epss 0.01

    Anuko Time Tracker is an open source, web-based time tracking application written in PHP. SQL injection vulnerability exist in multiple files in Time Tracker version 1.19.33.5606 and prior due to not properly checking of the "group" and "status" parameters in POST requests.…

  • CVE-2021-41262HigDec 16, 2021
    risk 0.00cvss 8.8epss 0.01

    Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 are subject to SQL injection attacks by users with "member" privilege. Users are advised to upgrade to version 0.9.6 as soon as possible. There…

  • CVE-2021-43830HigDec 14, 2021
    risk 0.00cvss 7.4epss 0.01

    OpenProject is a web-based project management software. OpenProject versions >= 12.0.0 are vulnerable to a SQL injection in the budgets module. For authenticated users with the "Edit budgets" permission, the request to reassign work packages to another budget unsufficiently…

  • CVE-2021-35414CriDec 3, 2021
    risk 0.00cvss 9.8epss 0.02

    Chamilo LMS v1.11.x was discovered to contain a SQL injection via the doc parameter in main/plagiarism/compilatio/upload.php.

  • CVE-2021-39179HigOct 29, 2021
    risk 0.00cvss 8.8epss 0.02

    DHIS 2 is an information system for data capture, management, validation, analytics and visualization. A SQL Injection vulnerability in the Tracker component in DHIS2 Server allows authenticated remote attackers to execute arbitrary SQL commands via unspecified vectors. This…

  • CVE-2021-37558CriAug 3, 2021
    risk 0.00cvss 9.8epss 0.02

    A SQL injection vulnerability in a MediaWiki script in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote unauthenticated attackers to execute arbitrary SQL commands via the host_name and service_description parameters. The vulnerability can be exploited only when a…

  • CVE-2021-23405HigJul 9, 2021
    risk 0.00cvss 8.3epss 0.02

    This affects the package pimcore/pimcore before 10.0.7. This issue exists due to the absence of check on the storeId parameter in the method collectionsActionGet and groupsActionGet method within the ClassificationstoreController class.

  • CVE-2021-32615CriMay 13, 2021
    risk 0.00cvss 9.8epss 0.02

    Piwigo 11.4.0 allows admin/user_list_backend.php order[0][dir] SQL Injection.

  • CVE-2020-15153HigApr 30, 2021
    risk 0.00cvss 8.2epss 0.02

    Ampache before version 4.2.2 allows unauthenticated users to perform SQL injection. Refer to the referenced GitHub Security Advisory for details and a workaround. This is fixed in version 4.2.2 and the development branch.

  • CVE-2020-24617HigFeb 19, 2021
    risk 0.00cvss 8.8epss 0.01

    Mailtrain through 1.24.1 allows SQL Injection in statsClickedSubscribersByColumn in lib/models/campaigns.js via /campaigns/clicked/ajax because variable column names are not properly escaped.

  • CVE-2021-21263HigJan 19, 2021
    risk 0.00cvss 7.2epss 0.02

    Laravel is a web application framework. Versions of Laravel before 6.20.11, 7.30.2 and 8.22.1 contain a query binding exploitation. This same exploit applies to the illuminate/database package which is used by Laravel. If a request is crafted where a field that is normally a…

  • CVE-2020-29437HigJan 5, 2021
    risk 0.00cvss 8.1epss 0.03

    SQL injection in the Buzz module of OrangeHRM through 4.6 allows remote authenticated attackers to execute arbitrary SQL commands via the orangehrmBuzzPlugin/lib/dao/BuzzDao.php loadMorePostsForm[profileUserId] parameter to the buzz/loadMoreProfile endpoint.