Weaknesses of type CWE-89

12,895 results

Injeção SQL

Ocorre quando entrada do usuário é concatenada diretamente em comandos SQL sem validação ou sanitização, permitindo que um atacante insira código SQL malicioso. O aplicativo executa a consulta alterada, comprometendo confidencialidade, integridade e disponibilidade dos dados.

Example

Um formulário de login que monta a query assim: `SELECT * FROM users WHERE email = '" + emailDoFormulario + "'`. Se o usuário digitar `admin'--`, a query vira `SELECT * FROM users WHERE email = 'admin'--'` e bypassa a validação de senha, autenticando como admin.

How to mitigate

Use prepared statements ou stored procedures com parâmetros vinculados (bind parameters). Em Java use PreparedStatement; em Python use placeholders com psycopg2 ou SQLAlchemy; em qualquer linguagem evite concatenação de strings. Combine com validação de entrada e princípio do menor privilégio no banco de dados.

CVE-2022-3120HIGHSourceCodester Clinics Patient Management System Login index.php sql injectionEPSS 0.8%CVE-2023-46453CRITICALCertain GL.iNet devices with 4.x firmware allow authentication bypass (resulting in administrative control of the device) via a username thaEPSS 0.8%CVE-2024-7636MEDIUMcode-projects Simple Ticket Booking Login authenticate.php sql injectionEPSS 0.8%CVE-2022-46047MEDIUMAeroCMS v0.0.1 is vulnerable to SQL Injection via the delete parameter.EPSS 0.8%CVE-2023-2672MEDIUMSourceCodester Lost and Found Information System GET Parameter view.php sql injectionEPSS 0.8%CVE-2023-1290MEDIUMSourceCodester Sales Tracker Management System view_client.php sql injectionEPSS 0.8%CVE-2023-1165MEDIUMZhong Bang CRMEB Java list sql injectionEPSS 0.8%CVE-2023-1416MEDIUMSimple Art Gallery adminHome.php sql injectionEPSS 0.8%CVE-2026-15335HIGHBooking Package <= 1.7.20 - Unauthenticated SQL Injection via 'email' Form ParameterEPSS 0.8%CVE-2023-6310MEDIUMSourceCodester Loan Management System deleteBorrower.php delete_borrower sql injectionEPSS 0.8%CVE-2023-1291MEDIUMSourceCodester Sales Tracker Management System manage_client.php sql injectionEPSS 0.8%CVE-2023-1292MEDIUMSourceCodester Sales Tracker Management System Master.php delete_client sql injectionEPSS 0.8%CVE-2023-1379MEDIUMSourceCodester Friendly Island Pizza Website and Ordering System POST Parameter addmem.php sql injectionEPSS 0.8%CVE-2023-6311MEDIUMSourceCodester Loan Management System Loan Type Page delete_ltype.php delete_ltype sql injectionEPSS 0.8%CVE-2023-6312MEDIUMSourceCodester Loan Management System Users Page deleteUser.php delete_user sql injectionEPSS 0.8%CVE-2025-26156HIGHA SQL Injection vulnerability was found in /shopping/track-orders.php in PHPGurukul Online Shopping Portal v2.1, which allows remote attackeEPSS 0.8%CVE-2020-4035MEDIUMDoS or local data modification via malicious record IDs in WatermelonDBEPSS 0.8%CVE-2022-43276HIGHCanteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the productId parameter at /php_action/fetchSelecEPSS 0.8%CVE-2022-43127HIGHOnline Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /appointments/uEPSS 0.8%CVE-2022-43126HIGHOnline Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/tests/maEPSS 0.8%