Beveiligingsadvies

CVE-2020-36112

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2021-01-04 14:46:37
Laatst bijgewerkt 2024-08-04 17:16:14
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

CSE Bookstore version 1.0 is vulnerable to time-based blind, boolean-based blind and OR error-based SQL injection in pubid parameter in bookPerPub.php and in cart.php. A successful exploitation of this vulnerability will lead to an attacker dumping the entire database on which the web application is running.