Unauthorized Access and Data Leakage via Union-Based SQL Injection — Summary: This vulnerability allows an attacker to run arbitrary SQL queries on the application’s database, which might result in unapproved access, data leaking, or even total system penetration. The technical information about the vulnerability, its effects, and suggested countermeasures are included in the report that follows.