SQL Injection Vulnerability in Online Book Store by Project Worlds
CVE-2020-19110
9.8CRITICAL
What is CVE-2020-19110?
The Online Book Store application version 1.0 is vulnerable to SQL Injection via the bookisbn parameter in the book.php file. This flaw allows a remote attacker to manipulate SQL queries by injecting arbitrary code, potentially leading to unauthorized access to the database and disclosure of sensitive information. It is crucial for users to apply patches or updates as they become available to mitigate the risks associated with this vulnerability.