Vulnerability Description
CSE Bookstore version 1.0 is vulnerable to time-based blind, boolean-based blind and OR error-based SQL injection in pubid parameter in bookPerPub.php and in cart.php. A successful exploitation of this vulnerability will lead to an attacker dumping the entire database on which the web application is running.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cse Bookstore Project | Cse Bookstore | 1.0 |
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/49314ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/49314ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2020-36112?
CVE-2020-36112 is a vulnerability with a CVSS score of 9.8 (CRITICAL). CSE Bookstore version 1.0 is vulnerable to time-based blind, boolean-based blind and OR error-based SQL injection in pubid parameter in bookPerPub.php and in cart.php. A successful exploitation of thi...
How severe is CVE-2020-36112?
CVE-2020-36112 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-36112?
Check the references section above for vendor advisories and patch information. Affected products include: Cse Bookstore Project Cse Bookstore.