Fallos del tipo CWE-89

12.948 resultados

Injeção de SQL

Ocorre quando dados fornecidos por um usuário são incorporados diretamente em comandos SQL sem validação ou sanitização, permitindo que um atacante modifique a lógica da consulta. O risco é grave: exposição de dados sensíveis, modificação ou deleção de registros, e até comprometimento do servidor de banco de dados.

Ejemplo

Um formulário de login que constrói a consulta como `SELECT * FROM users WHERE login = '` + entrada_do_usuario + `'` permite que alguém digite `admin' --` e contorne a verificação de senha, ou `' OR '1'='1` para listar todos os usuários.

Cómo mitigar

Use prepared statements ou stored procedures com parâmetros vinculados (nunca concatenação de strings). Se necessário filtrar, aplique whitelist rigorosa e escape adequado para o banco de dados específico. Implemente validação de entrada e princípio do menor privilégio na conta do banco.

CVE-2024-11250MEDIUMcode-projects Inventory Management editProduct.php sql injectionEPSS 0.7%CVE-2023-6607MEDIUMTongda OA 2017 delete.php sql injectionEPSS 0.7%CVE-2024-25213HIGHEmployee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /edit.php.EPSS 0.7%CVE-2025-1702HIGHUltimate Member <= 2.10.0 - Unauthenticated SQL Injection via search ParameterEPSS 0.7%CVE-2024-25212HIGHEmployee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /delete.php.EPSS 0.7%CVE-2023-1495MEDIUMRebuild list queryListOfConfig sql injectionEPSS 0.7%CVE-2025-10046MEDIUMELEX WooCommerce Google Shopping (Google Product Feed) <= 1.4.3 - Authenticated (Admin+) SQL InejctionEPSS 0.7%CVE-2023-2889CRITICALSQLi in Veon Computer's Service Tracking SoftwareEPSS 0.7%CVE-2024-1928MEDIUMSourceCodester Web-Based Student Clearance System Edit User Profile Page edit-admin.php sql injectionEPSS 0.7%CVE-2024-6672HIGHWhatsUp Gold getMonitorJoin SQL Injection Privilege Escalation VulnerabilityEPSS 0.7%CVE-2023-45377CRITICALIn the module "Chronopost Official" (chronopost) for PrestaShop, a guest can perform SQL injection. The script PHP `cancelSkybill.php` own aEPSS 0.7%CVE-2023-1407MEDIUMSourceCodester Student Study Center Desk Management System manage_user.php sql injectionEPSS 0.7%CVE-2014-125049MEDIUMtypcn Blogile server.js getNav sql injectionEPSS 0.7%CVE-2024-33409CRITICALSQL injection vulnerability in index.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SEPSS 0.7%CVE-2022-2017MEDIUMSourceCodester Prison Management System Visit view_visit.php sql injectionEPSS 0.7%CVE-2024-13007MEDIUMCodezips Event Management System contact.php sql injectionEPSS 0.7%CVE-2024-4093MEDIUMSourceCodester Simple Subscription Website view_application.php sql injectionEPSS 0.7%CVE-2024-33408CRITICALA SQL injection vulnerability in /model/get_classroom.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to exEPSS 0.7%CVE-2024-3466MEDIUMSourceCodester Laundry Management System Pengeluaran.php laporan_filter sql injectionEPSS 0.7%CVE-2024-33411CRITICALA SQL injection vulnerability in /model/get_admin_profile.php in Campcodes Complete Web-Based School Management System 1.0 allows attacker tEPSS 0.7%