getBookList of the file /admin/bookList?page=1&limit=10. The manipulation of the argument condition leads to sql injection.This vulnerability was named CVE-2025-2831. The attack can be initiated remotely. Furthermore, there is an exploit available.