PT-2025-51151 · Unknown · Computer Book Store
Jjjjjzr
·
Published
2025-12-14
·
Updated
2025-12-22
·
Jjjjjzr
·
Published
2025-12-14
·
Updated
2025-12-22
·
9.8
Critical
| Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
/admin delete.php file, specifically within an unknown function. Manipulation of the bookisbn argument can trigger the SQL injection. The attack can be initiated remotely, and the exploit has been publicly released./admin delete.php to prevent manipulation of the bookisbn argument.Exploit
Fix
SQL injection
Special Elements Injection