Weaknesses of type CWE-89

12,922 results

Injeção SQL

Ocorre quando entrada do usuário é concatenada diretamente em comandos SQL sem validação ou sanitização, permitindo que um atacante insira código SQL malicioso. O aplicativo executa a consulta alterada, comprometendo confidencialidade, integridade e disponibilidade dos dados.

Example

Um formulário de login que monta a query assim: `SELECT * FROM users WHERE email = '" + emailDoFormulario + "'`. Se o usuário digitar `admin'--`, a query vira `SELECT * FROM users WHERE email = 'admin'--'` e bypassa a validação de senha, autenticando como admin.

How to mitigate

Use prepared statements ou stored procedures com parâmetros vinculados (bind parameters). Em Java use PreparedStatement; em Python use placeholders com psycopg2 ou SQLAlchemy; em qualquer linguagem evite concatenação de strings. Combine com validação de entrada e princípio do menor privilégio no banco de dados.

CVE-2024-3442MEDIUMSourceCodester Prison Management System delete_leave.php sql injectionEPSS 0.7%CVE-2024-3466MEDIUMSourceCodester Laundry Management System Pengeluaran.php laporan_filter sql injectionEPSS 0.7%CVE-2023-1407MEDIUMSourceCodester Student Study Center Desk Management System manage_user.php sql injectionEPSS 0.7%CVE-2026-67854CRITICALSQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary codeEPSS 0.7%CVE-2024-3224MEDIUMSourceCodester PHP Task Management System task-details.php sql injectionEPSS 0.7%CVE-2023-1091CRITICALSQL Injection found in ALPATA's Licensed Warehousing Automation SystemEPSS 0.7%CVE-2022-38492HIGHAn issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. One parameter allows SQL injection. Version 2022.1.110.1.02 fixes theEPSS 0.7%CVE-2022-38490CRITICALAn issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Some parameters allow SQL injection. Version 2022.1.110.1.02 correctsEPSS 0.7%CVE-2024-0359HIGHcode-projects Simple Online Hotel Reservation System login.php sql injectionEPSS 0.7%CVE-2023-6903HIGHNetentsec NS-ASG Application Security Gateway sql injectionEPSS 0.7%CVE-2023-2962MEDIUMSourceCodester Faculty Evaluation System sql injectionEPSS 0.7%CVE-2023-5804HIGHPHPGurukul Nipah Virus Testing Management System login.php sql injectionEPSS 0.7%CVE-2024-0287MEDIUMKashipara Food Management System itemBillPdf.php sql injectionEPSS 0.7%CVE-2022-44120CRITICALdedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php.EPSS 0.7%CVE-2023-5794HIGHPHPGurukul Online Railway Catering System Login index.php sql injectionEPSS 0.7%CVE-2024-0655MEDIUMNovel-Plus list sql injectionEPSS 0.7%CVE-2023-5828HIGHNanning Ontall Longxing Industrial Development Zone Project Construction and Installation Management System login.aspx sql injectionEPSS 0.7%CVE-2023-1366MEDIUMSourceCodester Yoga Class Registration System manage_category.php query sql injectionEPSS 0.7%CVE-2024-25216CRITICALEmployee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the mailud parameter at /aprocess.php.EPSS 0.7%CVE-2023-24812HIGHSQL injection of notes/search-by-tagEPSS 0.7%