Every story tagged SQL Injection, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.
6 stories · open in the command center
A critical stored SQL injection vulnerability (CVSS 9.3) in OpenMeter versions 1.0.0-beta.218 through beta.231 allows attackers to execute arbitrary database queries by injecting malicious code through customer usage-attribution fields, potentially exposing sensitive customer data and compromising billing/metering operations. Organizations using affected OpenMeter versions face immediate risk to data confidentiality, integrity, and system availability, requiring urgent patching and review of access controls for customer creation/update permissions. This vulnerability highlights the importance of input validation in usage-based billing systems and demands immediate assessment of downstream impacts on revenue recognition and customer trust.
A critical vulnerability (CVSS 9.8) in HUMANIST Digital Human Resources version 26.0 allows attackers to exploit cleartext storage of sensitive information combined with SQL injection, enabling complete compromise of confidentiality, integrity, and availability without authentication or user interaction. Organizations using this HR system face immediate risk to employee data and system integrity, requiring urgent patching to version 26.1 and security posture reassessment of HR data handling practices. This incident underscores the importance of vendor security practices in critical business applications and highlights gaps in secure development standards among software providers.
Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to inject arbitrary SQL fragments by supplying an unvalidated direction value in the orderBy query parameter of the tag statistics endpoint. Attackers can craft a malicious direction string containing SQL subqueries that flows unsanitized into a Doctrine QueryBuilder ORDER BY clause, enabling time-based, boolean-oracle, and error-based extraction of sensitive data including long URLs, visitor records, IP addresses, geolocation data, user agents, and hashed API key secrets from any tenant.
Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to inject arbitrary SQL fragments by supplying an unvalidated direction value in the orderBy query parameter of the tag statistics endpoint. Attackers can craft a malicious direction string containing SQL subqueries that flows unsanitized into a Doctrine QueryBuilder ORDER BY clause, enabling time-based, boolean-oracle, and error-based extraction of sensitive data including long URLs, visitor records, IP addresses, geolocation data, user agents, and hashed API key secrets from any tenant.
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffic Analysis System allows SQL Injection. This issue affects Traffic Analysis System: from 30 before 34.
The rapid proliferation of AI-assisted "vibe-coded" applications has created a significant cybersecurity crisis, with thousands of hastily built apps exposing sensitive data like medical records, financial information, and customer logs due to basic security vulnerabilities. IT organizations must establish governance frameworks and security standards for citizen-developed applications, as the ease of AI-assisted development has outpaced security awareness and automated protections, creating organizational liability risks similar to shadow IT threats. The strategic imperative is clear: enterprises need policies distinguishing between low-risk personal applications and business-critical software, requiring appropriate security reviews before deployment regardless of development method.