SQL Injection Vulnerability in Online Book Store by Project Worlds
CVE-2020-19107
9.8CRITICAL
What is CVE-2020-19107?
An SQL Injection vulnerability exists in Online Book Store v1.0 that affects the 'isbn' parameter within the edit_book.php script. This flaw allows remote attackers to manipulate database queries, potentially enabling them to execute arbitrary code on the server. Such vulnerabilities pose a significant risk to application integrity and data security, making it crucial for users to apply necessary security patches or updates.