Fallos del tipo CWE-89

13.086 resultados

Injeção de SQL

Ocorre quando dados fornecidos por um usuário são incorporados diretamente em comandos SQL sem validação ou sanitização, permitindo que um atacante modifique a lógica da consulta. O risco é grave: exposição de dados sensíveis, modificação ou deleção de registros, e até comprometimento do servidor de banco de dados.

Ejemplo

Um formulário de login que constrói a consulta como `SELECT * FROM users WHERE login = '` + entrada_do_usuario + `'` permite que alguém digite `admin' --` e contorne a verificação de senha, ou `' OR '1'='1` para listar todos os usuários.

Cómo mitigar

Use prepared statements ou stored procedures com parâmetros vinculados (nunca concatenação de strings). Se necessário filtrar, aplique whitelist rigorosa e escape adequado para o banco de dados específico. Implemente validação de entrada e princípio do menor privilégio na conta do banco.

CVE-2025-2062MEDIUMprojectworlds Life Insurance Management System clientStatus.php sql injectionEPSS 0.5%CVE-2025-2034MEDIUMPHPGurukul Pre-School Enrollment System edit-class.php sql injectionEPSS 0.5%CVE-2025-2050MEDIUMPHPGurukul User Registration & Login and User Management System login.php sql injectionEPSS 0.5%CVE-2025-2060MEDIUMPHPGurukul Emergency Ambulance Hiring Portal admin-profile.php sql injectionEPSS 0.5%CVE-2024-7751MEDIUMSourceCodester Clinics Patient Management System update_medicine.php sql injectionEPSS 0.5%CVE-2025-2065MEDIUMprojectworlds Life Insurance Management System editAgent.php sql injectionEPSS 0.5%CVE-2024-7680MEDIUMitsourcecode Tailoring Management System incedit.php sql injectionEPSS 0.5%CVE-2025-2066MEDIUMprojectworlds Life Insurance Management System updateAgent.php sql injectionEPSS 0.5%CVE-2025-2067MEDIUMprojectworlds Life Insurance Management System search.php sql injectionEPSS 0.5%CVE-2023-7188MEDIUMShipping 100 Fahuo100 login.php sql injectionEPSS 0.5%CVE-2024-53506CRITICALA SQL injection vulnerability has been identified in Siyuan 3.1.11 via the ids array parameter in /batchGetBlockAttrs.EPSS 0.5%CVE-2026-12090MEDIUMTaskbuilder <= 5.0.8 - Authenticated (Subscriber+) SQL Injection via 'wppm_proj_filter' ParameterEPSS 0.5%CVE-2025-2064MEDIUMprojectworlds Life Insurance Management System deletePayment.php sql injectionEPSS 0.5%CVE-2026-15918HIGHVikAppointments – Services Booking Calendar <= 1.2.19 - Unauthenticated SQL InjectionEPSS 0.5%CVE-2024-7794MEDIUMitsourcecode Vehicle Management System mybill.php sql injectionEPSS 0.5%CVE-2026-2576HIGHBusiness Directory Plugin <= 6.4.21 - Unauthenticated SQL Injection via payment ParameterEPSS 0.5%CVE-2025-2033MEDIUMcode-projects Blood Bank Management System view_donor.php sql injectionEPSS 0.5%CVE-2025-1216MEDIUMywoa OaNoticeMapper.xml selectNoticeList sql injectionEPSS 0.5%CVE-2026-40331CRITICALMasa CMS unauthenticated SQL injection via altTable parameter in JSON APIEPSS 0.5%CVE-2024-37252CRITICALWordPress Email Subscribers by Icegram Express plugin <= 5.7.25 - SQL Injection vulnerabilityEPSS 0.5%