Fallos del tipo CWE-89

12.875 resultados

Injeção de SQL

Ocorre quando dados fornecidos por um usuário são incorporados diretamente em comandos SQL sem validação ou sanitização, permitindo que um atacante modifique a lógica da consulta. O risco é grave: exposição de dados sensíveis, modificação ou deleção de registros, e até comprometimento do servidor de banco de dados.

Ejemplo

Um formulário de login que constrói a consulta como `SELECT * FROM users WHERE login = '` + entrada_do_usuario + `'` permite que alguém digite `admin' --` e contorne a verificação de senha, ou `' OR '1'='1` para listar todos os usuários.

Cómo mitigar

Use prepared statements ou stored procedures com parâmetros vinculados (nunca concatenação de strings). Se necessário filtrar, aplique whitelist rigorosa e escape adequado para o banco de dados específico. Implemente validação de entrada e princípio do menor privilégio na conta do banco.

CVE-2023-7107HIGHcode-projects E-Commerce Website user_signup.php sql injectionEPSS 0.9%CVE-2022-47770CRITICALSerenissima Informatica Fast Checkin version v1.0 is vulnerable to Unauthenticated SQL Injection.EPSS 0.9%CVE-2025-25763CRITICALcrmeb CRMEB-KY v5.4.0 and before has a SQL Injection vulnerability at getRead() in /system/SystemDatabackupServices.phpEPSS 0.9%CVE-2025-13372MEDIUMPotential SQL injection in FilteredRelation column aliases on PostgreSQLEPSS 0.9%CVE-2023-36813HIGHKanboard Authenticated SQL Injections vulnerabilityEPSS 0.9%CVE-2020-10623—Multiple vulnerabilities could allow an attacker with low privileges to perform SQL injection on WebAccess/NMS (versions prior to 3.0.2) to EPSS 0.9%CVE-2023-3490CRITICALSQL Injection in fossbilling/fossbillingEPSS 0.9%CVE-2024-57657HIGHAn issue in the sqlg_vec_upd component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via craftEPSS 0.9%CVE-2024-57643HIGHAn issue in the box_deserialize_string component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS)EPSS 0.9%CVE-2024-57650HIGHAn issue in the qi_inst_state_free component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) viaEPSS 0.9%CVE-2024-57651HIGHAn issue in the jp_add component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQLEPSS 0.9%CVE-2024-57648HIGHAn issue in the itc_set_param_row component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via EPSS 0.9%CVE-2024-48427HIGHA SQL injection vulnerability in Sourcecodester Packers and Movers Management System v1.0 allows remote authenticated users to execute arbitEPSS 0.9%CVE-2020-21060HIGHSQL injection vulnerability found in PHPMyWind v.5.6 allows a remote attacker to gain privileges via the delete function of the administratoEPSS 0.9%CVE-2012-10047CRITICALCyclope Employee Surveillance Solution v6.x SQL InjectionEPSS 0.9%CVE-2023-38844HIGHSQL injection vulnerability in PMB v.7.4.7 and earlier allows a remote attacker to execute arbitrary code via the thesaurus parameter in expEPSS 0.9%CVE-2025-52664HIGHSQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted payloads are sent by loggEPSS 0.9%CVE-2025-30473HIGHApache Airflow Common SQL Provider: Remote Code Execution via Sql InjectionEPSS 0.9%CVE-2025-4464MEDIUMitsourcecode Gym Management System ajax.php sql injectionEPSS 0.9%CVE-2025-4456MEDIUMProject Worlds Car Rental Project signup.php sql injectionEPSS 0.9%