Vulnerability record · CVE-2020-29284 · published 2 December 2020
CVE-2020-29284: Multi restaurant table reservation system project multi restaurant table reservation system sql injection vulnerability
MMulti Restaurant Table Reservation System Project · Multi Restaurant Table Reservation System
The file view-chair-list.php in Multi Restaurant Table Reservation System 1.0 does not perform input validation on the table_id parameter which allows unauthenticated SQL Injection. An attacker can send malicious input in the GET request to /dashboard/view-chair-list.php?table_id= to trigger the vulnerability.
Description
The file view-chair-list.php in Multi Restaurant Table Reservation System 1.0 does not perform input validation on the table_id parameter which allows unauthenticated SQL Injection. An attacker can send malicious input in the GET request to /dashboard/view-chair-list.php?table_id= to trigger the vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/BigTiger2020/-Multi-Restaurant-Table-Reservation-System/blob/main/README.md | ExploitThird Party Advisory |
| https://www.exploit-db.com/exploits/48984 | ExploitThird Party AdvisoryVDB Entry |
| https://www.sourcecodester.com/php/14568/multi-restaurant-table-reservation-system-php-full-source-code.html | ProductThird Party Advisory |
| https://github.com/BigTiger2020/-Multi-Restaurant-Table-Reservation-System/blob/main/README.md | ExploitThird Party Advisory |
| https://www.exploit-db.com/exploits/48984 | ExploitThird Party AdvisoryVDB Entry |
| https://www.sourcecodester.com/php/14568/multi-restaurant-table-reservation-system-php-full-source-code.html | ProductThird Party Advisory |
Track CVE-2020-29284 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-29284), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.