← Vulnerability feed

Vulnerability record · CVE-2020-29284 · published 2 December 2020

CVE-2020-29284: Multi restaurant table reservation system project multi restaurant table reservation system sql injection vulnerability

MMulti Restaurant Table Reservation System Project · Multi Restaurant Table Reservation System

The file view-chair-list.php in Multi Restaurant Table Reservation System 1.0 does not perform input validation on the table_id parameter which allows unauthenticated SQL Injection. An attacker can send malicious input in the GET request to /dashboard/view-chair-list.php?table_id= to trigger the vulnerability.

9.8 CVSS 3.1 Critical EPSS 6.1% · top 6.8% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 7.5
6.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

The file view-chair-list.php in Multi Restaurant Table Reservation System 1.0 does not perform input validation on the table_id parameter which allows unauthenticated SQL Injection. An attacker can send malicious input in the GET request to /dashboard/view-chair-list.php?table_id= to trigger the vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-29284 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

5.4CVE-2020-35261Multi restaurant table reservation system project multi restaurant table reservation system cross-site scripting vulnerabilityCross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Restaurant Name field to /dashboard/…EPSS 1.0%5.4CVE-2020-36550Multi restaurant table reservation system project multi restaurant table reservation system cross-site scripting vulnerabilityCross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Table Name field to /dashboard/table…EPSS 1.0%5.4CVE-2020-36551Multi restaurant table reservation system project multi restaurant table reservation system cross-site scripting vulnerabilityCross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Item Name field to /dashboard/menu-l…EPSS 1.0%5.4CVE-2020-36552Multi restaurant table reservation system project multi restaurant table reservation system cross-site scripting vulnerabilityCross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Made field to /dashboard/menu-list.p…EPSS 1.0%5.4CVE-2020-36553Multi restaurant table reservation system project multi restaurant table reservation system cross-site scripting vulnerabilityCross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Area(food_type) field to /dashboard/…EPSS 1.0%5.4CVE-2021-44091Multi restaurant table reservation system project multi restaurant table reservation system cross-site scripting vulnerabilityA Cross-Site Scripting (XSS) vulnerability exists in Courcecodester Multi Restaurant Table Reservation System 1.0 in register.php via the (1) fullnam…EPSS 0.62%9.8CVE-2026-76461Cisco AsyncOS email parsing SQL injection allows root command executionCisco AsyncOS Software for Cisco Secure Email Gateway fails to properly validate email parsing input, allowing crafted email messages containing mali…KEVEPSS 28%analysed9.3CVE-2026-9586Sangoma Switchvox unauthenticated SQL injection in /pa endpointSangoma Switchvox SMB Edition 8.3 (104997) fails to sanitize the PhoneIP value from XML content beginning with <PolycomIPPhone> before concatenating …KEVEPSS 19%analysed

Source: NIST National Vulnerability Database (record CVE-2020-29284), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.