CVE-2020-36112: Cse Bookstore Project Cse Bookstore

Critical severity, CVSS 9.8. EPSS: 18.1% chance of exploitation in the next 30 days.

CSE Bookstore version 1.0 is vulnerable to time-based blind, boolean-based blind and OR error-based SQL injection in pubid parameter in bookPerPub.php and in cart.php. A successful exploitation of this vulnerability will lead to an attacker dumping the entire database on which the web application is running.

Affected products

Published 2021-01-04. Last modified 2026-06-17.