Falhas do tipo CWE-89

12.895 resultados

Injeção de SQL

Fraqueza onde entrada do usuário é concatenada diretamente em comandos SQL sem validação ou sanitização, permitindo que um atacante insira código SQL malicioso. O banco de dados executa comandos não intencionais, comprometendo confidencialidade, integridade e disponibilidade dos dados.

Exemplo

Um formulário de login concatena o usuário digitado direto na query: `SELECT * FROM users WHERE login = '` + input + `'`. Se o usuário digita `admin' OR '1'='1`, a query vira `SELECT * FROM users WHERE login = 'admin' OR '1'='1'`, retornando todos os usuários e burlando autenticação.

Como mitigar

Use prepared statements (consultas parametrizadas) com placeholders, nunca concatene entrada do usuário. Valide e restrinja entrada (whitelist), aplique princípio do menor privilégio na conta do BD e use WAF como camada adicional.

CVE-2024-7219MEDIUMSourceCodester/Campcodes School Log Management System ajax.php sql injectionEPSS 0.8%CVE-2023-30077CRITICALJudging Management System v1.0 by oretnom23 was discovered to vulnerable to SQL injection via /php-jms/review_result.php?mainevent_id=, mainEPSS 0.8%CVE-2022-43081HIGHFast Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the component /fastfood/purchase.php.EPSS 0.8%CVE-2026-72899CRITICALMetabase SQL injection via public card or dashboardEPSS 0.8%CVE-2022-41570CRITICALAn issue was discovered in EyesOfNetwork (EON) through 5.3.11. Unauthenticated SQL injection can occur.EPSS 0.8%CVE-2024-11646MEDIUM1000 Projects Beauty Parlour Management System edit-services.php sql injectionEPSS 0.8%CVE-2024-5984MEDIUMitsourcecode Online Bookstore book.php sql injectionEPSS 0.8%CVE-2024-25866HIGHA SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commaEPSS 0.8%CVE-2024-25469HIGHSQL Injection vulnerability in CRMEB crmeb_java v.1.3.4 and before allows a remote attacker to obtain sensitive information via the latitudeEPSS 0.8%CVE-2024-57634HIGHAn issue in the exp_copy component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statementsEPSS 0.8%CVE-2026-48381CRITICALAdobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)EPSS 0.8%CVE-2022-2656MEDIUMSourceCodester Multi Language Hotel Management Software sql injectionEPSS 0.8%CVE-2024-57632HIGHAn issue in the is_column_unique component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL stEPSS 0.8%CVE-2024-57621HIGHAn issue in the GDKanalytical_correlation component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafEPSS 0.8%CVE-2023-5261MEDIUMTongda OA 2017 delete.php sql injectionEPSS 0.8%CVE-2024-57625HIGHAn issue in the merge_table_prune_and_unionize component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via EPSS 0.8%CVE-2023-5265MEDIUMTongda OA 2017 delete.php sql injectionEPSS 0.8%CVE-2023-5267MEDIUMTongda OA 2017 delete.php sql injectionEPSS 0.8%CVE-2024-25239CRITICALSQL Injection vulnerability in Sourcecodester Employee Management System v1.0 allows attackers to run arbitrary SQL commands via crafted POSEPSS 0.8%CVE-2022-45206CRITICALJeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check.EPSS 0.8%