Weaknesses of type CWE-89

12,895 results

Injeção SQL

Ocorre quando entrada do usuário é concatenada diretamente em comandos SQL sem validação ou sanitização, permitindo que um atacante insira código SQL malicioso. O aplicativo executa a consulta alterada, comprometendo confidencialidade, integridade e disponibilidade dos dados.

Example

Um formulário de login que monta a query assim: `SELECT * FROM users WHERE email = '" + emailDoFormulario + "'`. Se o usuário digitar `admin'--`, a query vira `SELECT * FROM users WHERE email = 'admin'--'` e bypassa a validação de senha, autenticando como admin.

How to mitigate

Use prepared statements ou stored procedures com parâmetros vinculados (bind parameters). Em Java use PreparedStatement; em Python use placeholders com psycopg2 ou SQLAlchemy; em qualquer linguagem evite concatenação de strings. Combine com validação de entrada e princípio do menor privilégio no banco de dados.

CVE-2024-7219MEDIUMSourceCodester/Campcodes School Log Management System ajax.php sql injectionEPSS 0.8%CVE-2023-30077CRITICALJudging Management System v1.0 by oretnom23 was discovered to vulnerable to SQL injection via /php-jms/review_result.php?mainevent_id=, mainEPSS 0.8%CVE-2022-43081HIGHFast Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the component /fastfood/purchase.php.EPSS 0.8%CVE-2026-72899CRITICALMetabase SQL injection via public card or dashboardEPSS 0.8%CVE-2022-41570CRITICALAn issue was discovered in EyesOfNetwork (EON) through 5.3.11. Unauthenticated SQL injection can occur.EPSS 0.8%CVE-2024-11646MEDIUM1000 Projects Beauty Parlour Management System edit-services.php sql injectionEPSS 0.8%CVE-2024-5984MEDIUMitsourcecode Online Bookstore book.php sql injectionEPSS 0.8%CVE-2024-25866HIGHA SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commaEPSS 0.8%CVE-2024-25469HIGHSQL Injection vulnerability in CRMEB crmeb_java v.1.3.4 and before allows a remote attacker to obtain sensitive information via the latitudeEPSS 0.8%CVE-2024-57634HIGHAn issue in the exp_copy component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statementsEPSS 0.8%CVE-2026-48381CRITICALAdobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)EPSS 0.8%CVE-2022-2656MEDIUMSourceCodester Multi Language Hotel Management Software sql injectionEPSS 0.8%CVE-2024-57632HIGHAn issue in the is_column_unique component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL stEPSS 0.8%CVE-2024-57621HIGHAn issue in the GDKanalytical_correlation component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafEPSS 0.8%CVE-2023-5261MEDIUMTongda OA 2017 delete.php sql injectionEPSS 0.8%CVE-2024-57625HIGHAn issue in the merge_table_prune_and_unionize component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via EPSS 0.8%CVE-2023-5265MEDIUMTongda OA 2017 delete.php sql injectionEPSS 0.8%CVE-2023-5267MEDIUMTongda OA 2017 delete.php sql injectionEPSS 0.8%CVE-2024-25239CRITICALSQL Injection vulnerability in Sourcecodester Employee Management System v1.0 allows attackers to run arbitrary SQL commands via crafted POSEPSS 0.8%CVE-2022-45206CRITICALJeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check.EPSS 0.8%