CVE-2020-29284
02.12.2020, 22:15
The file view-chair-list.php in Multi Restaurant Table Reservation System 1.0 does not perform input validation on the table_id parameter which allows unauthenticated SQL Injection. An attacker can send malicious input in the GET request to /dashboard/view-chair-list.php?table_id= to trigger the vulnerability.
Vendor | Product | Version |
---|---|---|
multi_restaurant_table_reservation_system_project | multi_restaurant_table_reservation_system | 1.0 |
𝑥
= Vulnerable software versions
References