The 'bookisbn' parameter of the cart.php resource does not validate the characters received and they are sent unfiltered to the database.
The 'bookisbn' parameter of the cart.php resource does not validate the characters received and they are sent unfiltered to the database.