Falhas do tipo CWE-89

12.881 resultados

Injeção de SQL

Fraqueza onde entrada do usuário é concatenada diretamente em comandos SQL sem validação ou sanitização, permitindo que um atacante insira código SQL malicioso. O banco de dados executa comandos não intencionais, comprometendo confidencialidade, integridade e disponibilidade dos dados.

Exemplo

Um formulário de login concatena o usuário digitado direto na query: `SELECT * FROM users WHERE login = '` + input + `'`. Se o usuário digita `admin' OR '1'='1`, a query vira `SELECT * FROM users WHERE login = 'admin' OR '1'='1'`, retornando todos os usuários e burlando autenticação.

Como mitigar

Use prepared statements (consultas parametrizadas) com placeholders, nunca concatene entrada do usuário. Valide e restrinja entrada (whitelist), aplique princípio do menor privilégio na conta do BD e use WAF como camada adicional.

CVE-2022-43352HIGHSanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-sms/classes/Master.EPSS 0.9%CVE-2022-41551HIGHGarage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/editorder.php.EPSS 0.9%CVE-2022-43355HIGHSanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-sms/classes/Master.EPSS 0.9%CVE-2023-26093CRITICALLiima before 1.17.28 allows Hibernate query language (HQL) injection, related to colToSort in the deployment filter.EPSS 0.9%CVE-2024-50717CRITICALSQL injection vulnerability in Smart Agent v.1.1.0 allows a remote attacker to execute arbitrary code via the client parameter in the /recupEPSS 0.9%CVE-2023-4740MEDIUMIBOS OA Delete Draft delDraft&archiveId=0 sql injectionEPSS 0.9%CVE-2024-50716CRITICALSQL injection vulnerability in Smart Agent v.1.1.0 allows a remote attacker to execute arbitrary code via the id parameter in the /sendPushMEPSS 0.9%CVE-2022-43022MEDIUMOpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag deletion function.EPSS 0.9%CVE-2022-43021MEDIUMOpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the entriesPerPage variable.EPSS 0.9%CVE-2022-43023MEDIUMOpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.EPSS 0.9%CVE-2022-43020MEDIUMOpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag update function.EPSS 0.9%CVE-2023-48863HIGHSEMCMS 3.9 is vulnerable to SQL Injection. Due to the lack of security checks on the input of the application, the attacker uses the existinEPSS 0.9%CVE-2023-22727CRITICALDatabase Query::offset() and limit() vulnerable to SQL injection in cakephpEPSS 0.9%CVE-2022-41731HIGHIBM Watson Knowledge Catalog on Cloud Pak SQL injectionEPSS 0.9%CVE-2024-30241HIGHWordPress ProfileGrid – User Profiles, Memberships, Groups and Communities plugin <= 5.7.1 - Contributor+ SQL Injection vulnerabilityEPSS 0.9%CVE-2015-10034MEDIUMj-nowak workout-organizer sql injectionEPSS 0.9%CVE-2020-13590MEDIUMMultiple exploitable SQL injection vulnerabilities exist in the 'entities/fields' page of the Rukovoditel Project Management App 2.7.2. A spEPSS 0.9%CVE-2023-6652HIGHcode-projects Matrimonial Site register.php register sql injectionEPSS 0.9%CVE-2025-63689CRITICALMultiple SQL injection vulnerabilitites in ycf1998 money-pos system before commit 11f276bd20a41f089298d804e43cb1c39d041e59 (2025-09-14) alloEPSS 0.9%CVE-2023-6651HIGHcode-projects Matrimonial Site sql injectionEPSS 0.9%