PT-2025-35377 · Unknown · Sourcecodester Online-Book-Store
Xyz123
·
Published
2025-08-30
·
Updated
2025-08-30
·
CVE-2025-9700
Xyz123
·
Published
2025-08-30
·
Updated
2025-08-30
·
CVE-2025-9700
7.5
High
Base vector | Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
SourceCodester Online Book Store version 1.0
Description:
A SQL injection issue exists due to the manipulation of the `pubid` parameter when processing the `/publisher list.php` file. This allows for remote attacks. The exploit has been published.
Recommendations:
As a temporary workaround, restrict access to the `/publisher list.php` file to minimize the risk of exploitation.
Avoid using the `pubid` parameter in the affected API endpoint `/publisher list.php` until the issue is resolved.
Exploit
Fix
Special Elements Injection
SQL injection