Fallos del tipo CWE-89

12.890 resultados

Injeção de SQL

Ocorre quando dados fornecidos por um usuário são incorporados diretamente em comandos SQL sem validação ou sanitização, permitindo que um atacante modifique a lógica da consulta. O risco é grave: exposição de dados sensíveis, modificação ou deleção de registros, e até comprometimento do servidor de banco de dados.

Ejemplo

Um formulário de login que constrói a consulta como `SELECT * FROM users WHERE login = '` + entrada_do_usuario + `'` permite que alguém digite `admin' --` e contorne a verificação de senha, ou `' OR '1'='1` para listar todos os usuários.

Cómo mitigar

Use prepared statements ou stored procedures com parâmetros vinculados (nunca concatenação de strings). Se necessário filtrar, aplique whitelist rigorosa e escape adequado para o banco de dados específico. Implemente validação de entrada e princípio do menor privilégio na conta do banco.

CVE-2022-43352HIGHSanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-sms/classes/Master.EPSS 0.9%CVE-2022-41551HIGHGarage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/editorder.php.EPSS 0.9%CVE-2022-43355HIGHSanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-sms/classes/Master.EPSS 0.9%CVE-2023-26093CRITICALLiima before 1.17.28 allows Hibernate query language (HQL) injection, related to colToSort in the deployment filter.EPSS 0.9%CVE-2024-50717CRITICALSQL injection vulnerability in Smart Agent v.1.1.0 allows a remote attacker to execute arbitrary code via the client parameter in the /recupEPSS 0.9%CVE-2023-4740MEDIUMIBOS OA Delete Draft delDraft&archiveId=0 sql injectionEPSS 0.9%CVE-2024-50716CRITICALSQL injection vulnerability in Smart Agent v.1.1.0 allows a remote attacker to execute arbitrary code via the id parameter in the /sendPushMEPSS 0.9%CVE-2022-43022MEDIUMOpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag deletion function.EPSS 0.9%CVE-2022-43021MEDIUMOpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the entriesPerPage variable.EPSS 0.9%CVE-2022-43023MEDIUMOpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.EPSS 0.9%CVE-2022-43020MEDIUMOpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag update function.EPSS 0.9%CVE-2023-48863HIGHSEMCMS 3.9 is vulnerable to SQL Injection. Due to the lack of security checks on the input of the application, the attacker uses the existinEPSS 0.9%CVE-2023-22727CRITICALDatabase Query::offset() and limit() vulnerable to SQL injection in cakephpEPSS 0.9%CVE-2022-41731HIGHIBM Watson Knowledge Catalog on Cloud Pak SQL injectionEPSS 0.9%CVE-2024-30241HIGHWordPress ProfileGrid – User Profiles, Memberships, Groups and Communities plugin <= 5.7.1 - Contributor+ SQL Injection vulnerabilityEPSS 0.9%CVE-2015-10034MEDIUMj-nowak workout-organizer sql injectionEPSS 0.9%CVE-2020-13590MEDIUMMultiple exploitable SQL injection vulnerabilities exist in the 'entities/fields' page of the Rukovoditel Project Management App 2.7.2. A spEPSS 0.9%CVE-2025-63689CRITICALMultiple SQL injection vulnerabilitites in ycf1998 money-pos system before commit 11f276bd20a41f089298d804e43cb1c39d041e59 (2025-09-14) alloEPSS 0.9%CVE-2023-6652HIGHcode-projects Matrimonial Site register.php register sql injectionEPSS 0.9%CVE-2023-6651HIGHcode-projects Matrimonial Site sql injectionEPSS 0.9%