Fallos del tipo CWE-89

13.150 resultados

Injeção de SQL

Ocorre quando dados fornecidos por um usuário são incorporados diretamente em comandos SQL sem validação ou sanitização, permitindo que um atacante modifique a lógica da consulta. O risco é grave: exposição de dados sensíveis, modificação ou deleção de registros, e até comprometimento do servidor de banco de dados.

Ejemplo

Um formulário de login que constrói a consulta como `SELECT * FROM users WHERE login = '` + entrada_do_usuario + `'` permite que alguém digite `admin' --` e contorne a verificação de senha, ou `' OR '1'='1` para listar todos os usuários.

Cómo mitigar

Use prepared statements ou stored procedures com parâmetros vinculados (nunca concatenação de strings). Se necessário filtrar, aplique whitelist rigorosa e escape adequado para o banco de dados específico. Implemente validação de entrada e princípio do menor privilégio na conta do banco.

CVE-2025-11662MEDIUMSourceCodester Best Salon Management System booking.php sql injectionEPSS 0.5%CVE-2019-25221MEDIUMResponsive Filterable Portfolio <=1.0.8 - Authenticated (Admin+) SQL InjectionEPSS 0.5%CVE-2025-11075MEDIUMCampcodes Online Learning Management System de_activate.php sql injectionEPSS 0.5%CVE-2025-11473MEDIUMSourceCodester Hotel and Lodge Management System edit_curr.php sql injectionEPSS 0.5%CVE-2024-7750MEDIUMSourceCodester Clinics Patient Management System medicines.php sql injectionEPSS 0.5%CVE-2024-10297MEDIUMPHPGurukul Medical Card Generation System Managecard Edit Image Page changeimage.php sql injectionEPSS 0.5%CVE-2024-46374CRITICALBest House Rental Management System 1.0 contains a SQL injection vulnerability in the delete_category() function of the file rental/admin_clEPSS 0.5%CVE-2025-2046MEDIUMSourceCodester Best Employee Management System print1.php sql injectionEPSS 0.5%CVE-2024-47223CRITICALA vulnerability in the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unEPSS 0.5%CVE-2025-8185MEDIUM1000 Projects ABC Courier Management System getbyid.php sql injectionEPSS 0.5%CVE-2026-85388HIGHWorklenz through 3.0.0 SQL Injection via the sort-field Query ParameterEPSS 0.5%CVE-2025-56074CRITICALA SQL Injection vulnerability was discovered in the foreigner-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management SysteEPSS 0.5%CVE-2026-76426MEDIUMCisco ISE REST API SQL Injection VulnerabilityEPSS 0.5%CVE-2026-5134CRITICALSQLi in Loca Software's CMSEPSS 0.5%CVE-2017-20282HIGHJoomla! Component jCart for OpenCart 2.0 SQL InjectionEPSS 0.5%CVE-2026-40822MEDIUMAuthenticated SQLi in DevSerialReset functionEPSS 0.5%CVE-2022-39069MEDIUMThere is a SQL injection vulnerability in ZTE ZAIP-AIE. Due to lack of input verification by the server, an attacker could trigger an attackEPSS 0.5%CVE-2024-51101CRITICALPHPGURUKUL Restaurant Table Booking System using PHP and MySQL v1.0 was discovered to contain a SQL injection vulnerability via the searchdaEPSS 0.5%CVE-2024-6041MEDIUMitsourcecode Gym Management System manage_user.php sql injectionEPSS 0.5%CVE-2026-2397CRITICALSQLi in AdamPOS' MobilMen 20TEPSS 0.5%