Fallos del tipo CWE-89

12.916 resultados

Injeção de SQL

Ocorre quando dados fornecidos por um usuário são incorporados diretamente em comandos SQL sem validação ou sanitização, permitindo que um atacante modifique a lógica da consulta. O risco é grave: exposição de dados sensíveis, modificação ou deleção de registros, e até comprometimento do servidor de banco de dados.

Ejemplo

Um formulário de login que constrói a consulta como `SELECT * FROM users WHERE login = '` + entrada_do_usuario + `'` permite que alguém digite `admin' --` e contorne a verificação de senha, ou `' OR '1'='1` para listar todos os usuários.

Cómo mitigar

Use prepared statements ou stored procedures com parâmetros vinculados (nunca concatenação de strings). Se necessário filtrar, aplique whitelist rigorosa e escape adequado para o banco de dados específico. Implemente validação de entrada e princípio do menor privilégio na conta do banco.

CVE-2022-3122MEDIUMSourceCodester Clinics Patient Management System medicine_details.php sql injectionEPSS 0.8%CVE-2025-25357HIGHA SQL Injection vulnerability was found in /admin/contactus.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execEPSS 0.8%CVE-2024-3255MEDIUMSourceCodester Internship Portal Management System edit_admin_query.php sql injectionEPSS 0.8%CVE-2025-25354HIGHA SQL Injection was found in /admin/admin-profile.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrEPSS 0.8%CVE-2025-25352HIGHA SQL Injection vulnerability was found in /admin/aboutus.php in PHPGurukul Land Record System v1.0, which allows remote attackers to executEPSS 0.8%CVE-2025-25355HIGHA SQL Injection vulnerability was found in /admin/bwdates-reports-details.php in PHPGurukul Land Record System v1.0, which allows remote attEPSS 0.8%CVE-2020-36768HIGHrl-institut NESP2 database.py sql injectionEPSS 0.8%CVE-2024-3259MEDIUMSourceCodester Internship Portal Management System delete_activity.php sql injectionEPSS 0.8%CVE-2025-25356HIGHA SQL Injection vulnerability was found in /admin/bwdates-reports-details.php in PHPGurukul Land Record System v1.0, which allows remote attEPSS 0.8%CVE-2025-25387HIGHA SQL Injection vulnerability was found in /admin/manage-propertytype.php in PHPGurukul Land Record System v1.0, which allows remote attackeEPSS 0.8%CVE-2023-49750CRITICALWordPress Couponis Demo Plugin < 2.2 is vulnerable to SQL InjectionEPSS 0.8%CVE-2023-3478MEDIUMIBOS OA Add User edit&op=member actionEdit sql injectionEPSS 0.8%CVE-2024-10376MEDIUMESAFENET CDG AutoSignService.java actionPassOrNotAutoSign sql injectionEPSS 0.8%CVE-2025-2217MEDIUMzzskzy Warehouse Refinement Management System getAdyData.ashx ProcessRequest sql injectionEPSS 0.8%CVE-2023-3383MEDIUMSourceCodester Game Result Matrix System GET Parameter athlete-profile.php sql injectionEPSS 0.8%CVE-2024-3465MEDIUMSourceCodester Laundry Management System Transaki.php laporan_filter sql injectionEPSS 0.8%CVE-2024-3088HIGHPHPGurukul Emergency Ambulance Hiring Portal Forgot Password Page forgot-password.php sql injectionEPSS 0.8%CVE-2023-31842HIGHSourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/index.php?page=edit_faculty&id=.EPSS 0.8%CVE-2024-30938CRITICALSQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID parameter in the SEMCMS_UserEPSS 0.8%CVE-2026-44381CRITICALMISP: SQL injection via unvalidated ordering parameters in event and shadow attribute listingsEPSS 0.8%