PT-2021-23753 · Unknown · Projectsworlds Online Book Store Php

Khanhchauminh

·

Published

2021-12-22

·

Updated

2021-12-28

·

CVE-2021-43155

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Projectsworlds Online Book Store PHP version 1.0
Description The issue concerns SQL injection via the bookisbn parameter in the "cart.php" file. This allows for potential manipulation of database queries.
Recommendations For Projectsworlds Online Book Store PHP version 1.0, consider validating and sanitizing user input for the bookisbn parameter in the "cart.php" file to prevent SQL injection attacks. As a temporary workaround, restrict access to the "cart.php" file until a proper fix is implemented.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-43155

Affected Products

Projectsworlds Online Book Store Php