SQL Injection Vulnerability in Online Book Store by Project Worlds
CVE-2020-19109
9.8CRITICAL
What is CVE-2020-19109?
An SQL Injection vulnerability exists in Online Book Store v1.0, specifically through the bookisbn parameter in admin_edit.php. This flaw enables remote attackers to manipulate SQL queries, potentially allowing the execution of arbitrary code within the application, posing significant risks to data integrity and application security.