Falhas do tipo CWE-89

12.903 resultados

Injeção de SQL

Fraqueza onde entrada do usuário é concatenada diretamente em comandos SQL sem validação ou sanitização, permitindo que um atacante insira código SQL malicioso. O banco de dados executa comandos não intencionais, comprometendo confidencialidade, integridade e disponibilidade dos dados.

Exemplo

Um formulário de login concatena o usuário digitado direto na query: `SELECT * FROM users WHERE login = '` + input + `'`. Se o usuário digita `admin' OR '1'='1`, a query vira `SELECT * FROM users WHERE login = 'admin' OR '1'='1'`, retornando todos os usuários e burlando autenticação.

Como mitigar

Use prepared statements (consultas parametrizadas) com placeholders, nunca concatene entrada do usuário. Valide e restrinja entrada (whitelist), aplique princípio do menor privilégio na conta do BD e use WAF como camada adicional.

CVE-2022-45041HIGHSQL Injection exits in xinhu < 2.5.0EPSS 0.8%CVE-2024-3420MEDIUMSourceCodester Online Courseware saveedit.php sql injectionEPSS 0.8%CVE-2023-3383MEDIUMSourceCodester Game Result Matrix System GET Parameter athlete-profile.php sql injectionEPSS 0.8%CVE-2023-25700HIGHWordPress Tutor LMS Plugin <= 2.1.10 is vulnerable to SQL InjectionEPSS 0.8%CVE-2024-3417MEDIUMSourceCodester Online Courseware saveeditt.php sql injectionEPSS 0.8%CVE-2026-44381CRITICALMISP: SQL injection via unvalidated ordering parameters in event and shadow attribute listingsEPSS 0.8%CVE-2024-57656HIGHAn issue in the sqlc_add_distinct_node component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS)EPSS 0.8%CVE-2024-57653HIGHAn issue in the qst_vec_set_copy component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via cEPSS 0.8%CVE-2024-8368MEDIUMcode-projects Hospital Management System Login index.php sql injectionEPSS 0.8%CVE-2022-45278HIGHJizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /index.php/admins/Fields/get_fields.html component.EPSS 0.8%CVE-2024-57642HIGHAn issue in the dfe_inx_op_col_def_table component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoEPSS 0.8%CVE-2023-22583CRITICALSQL Injection in Danfoss AK-EM100EPSS 0.8%CVE-2023-49548HIGHCustomer Support System v1 was discovered to contain a SQL injection vulnerability via the lastname parameter at /customer_support/ajax.php?EPSS 0.8%CVE-2023-49546HIGHCustomer Support System v1 was discovered to contain a SQL injection vulnerability via the email parameter at /customer_support/ajax.php.EPSS 0.8%CVE-2024-1927MEDIUMSourceCodester Web-Based Student Clearance System login.php sql injectionEPSS 0.8%CVE-2023-25223HIGHCRMEB <=1.3.4 is vulnerable to SQL Injection via /api/admin/user/list.EPSS 0.8%CVE-2024-57652HIGHAn issue in the numeric_to_dv component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafEPSS 0.8%CVE-2022-44140HIGHJizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /Member/memberedit.html component.EPSS 0.8%CVE-2024-57658HIGHAn issue in the sql_tree_hash_1 component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crEPSS 0.8%CVE-2024-9678MEDIUMAn SQL Injection vulnerability existed in DLP Extension 11.11.1.3. The vulnerability allowed an attacker to perform arbitrary SQL queries pEPSS 0.8%