SQL Injection Flaw in Online Book Store by Project World
CVE-2020-19112
9.8CRITICAL
What is CVE-2020-19112?
The Online Book Store application v1.0 contains an SQL Injection vulnerability that can be exploited through the 'bookisbn' parameter in 'admin_delete.php'. This flaw allows remote attackers to manipulate database queries, potentially executing arbitrary code and compromising the application’s integrity and security.