Weaknesses of type CWE-89

12,903 results

Injeção SQL

Ocorre quando entrada do usuário é concatenada diretamente em comandos SQL sem validação ou sanitização, permitindo que um atacante insira código SQL malicioso. O aplicativo executa a consulta alterada, comprometendo confidencialidade, integridade e disponibilidade dos dados.

Example

Um formulário de login que monta a query assim: `SELECT * FROM users WHERE email = '" + emailDoFormulario + "'`. Se o usuário digitar `admin'--`, a query vira `SELECT * FROM users WHERE email = 'admin'--'` e bypassa a validação de senha, autenticando como admin.

How to mitigate

Use prepared statements ou stored procedures com parâmetros vinculados (bind parameters). Em Java use PreparedStatement; em Python use placeholders com psycopg2 ou SQLAlchemy; em qualquer linguagem evite concatenação de strings. Combine com validação de entrada e princípio do menor privilégio no banco de dados.

CVE-2022-45041HIGHSQL Injection exits in xinhu < 2.5.0EPSS 0.8%CVE-2024-3420MEDIUMSourceCodester Online Courseware saveedit.php sql injectionEPSS 0.8%CVE-2023-3383MEDIUMSourceCodester Game Result Matrix System GET Parameter athlete-profile.php sql injectionEPSS 0.8%CVE-2023-25700HIGHWordPress Tutor LMS Plugin <= 2.1.10 is vulnerable to SQL InjectionEPSS 0.8%CVE-2024-3417MEDIUMSourceCodester Online Courseware saveeditt.php sql injectionEPSS 0.8%CVE-2026-44381CRITICALMISP: SQL injection via unvalidated ordering parameters in event and shadow attribute listingsEPSS 0.8%CVE-2024-57656HIGHAn issue in the sqlc_add_distinct_node component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS)EPSS 0.8%CVE-2024-57653HIGHAn issue in the qst_vec_set_copy component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via cEPSS 0.8%CVE-2024-8368MEDIUMcode-projects Hospital Management System Login index.php sql injectionEPSS 0.8%CVE-2022-45278HIGHJizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /index.php/admins/Fields/get_fields.html component.EPSS 0.8%CVE-2024-57642HIGHAn issue in the dfe_inx_op_col_def_table component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoEPSS 0.8%CVE-2023-22583CRITICALSQL Injection in Danfoss AK-EM100EPSS 0.8%CVE-2023-49548HIGHCustomer Support System v1 was discovered to contain a SQL injection vulnerability via the lastname parameter at /customer_support/ajax.php?EPSS 0.8%CVE-2023-49546HIGHCustomer Support System v1 was discovered to contain a SQL injection vulnerability via the email parameter at /customer_support/ajax.php.EPSS 0.8%CVE-2024-1927MEDIUMSourceCodester Web-Based Student Clearance System login.php sql injectionEPSS 0.8%CVE-2023-25223HIGHCRMEB <=1.3.4 is vulnerable to SQL Injection via /api/admin/user/list.EPSS 0.8%CVE-2024-57652HIGHAn issue in the numeric_to_dv component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafEPSS 0.8%CVE-2022-44140HIGHJizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /Member/memberedit.html component.EPSS 0.8%CVE-2024-57658HIGHAn issue in the sql_tree_hash_1 component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crEPSS 0.8%CVE-2024-9678MEDIUMAn SQL Injection vulnerability existed in DLP Extension 11.11.1.3. The vulnerability allowed an attacker to perform arbitrary SQL queries pEPSS 0.8%