Summary: The id parameter in detail.php of Online Book Store v1.0 is vulnerable to union-based blind SQL injection, which leads to the ability to retrieve all databases. Reference Links(if available): https://www.sourcecodester.com/download-code?nid=14383&title=Online+Book+Store https://www.sourcecodester.com/php/14383/online-book-store.html https://github.com/TCSWT/Online-Book-Store/blob/main/Online-Book-Store.md CVSS Score (if available) v2: / MEDIUM v3: / Links to Exploits(if available) Post navigation CVE-2020-7848 CVE-2021-22856