PT-2020-17133 · Unknown · Multi Restaurant Table Reservation System

Yunaranyancat

·

Published

2020-12-02

·

Updated

2020-12-04

·

CVE-2020-29284

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Multi Restaurant Table Reservation System version 1.0
Description The issue arises from the lack of input validation on the table id parameter in the file view-chair-list.php, allowing unauthenticated SQL Injection. An attacker can exploit this by sending malicious input in the GET request to "/dashboard/view-chair-list.php?table id=".
Recommendations For Multi Restaurant Table Reservation System version 1.0, consider disabling the view-chair-list.php file or restricting access to the "/dashboard/view-chair-list.php" endpoint until a patch is available. Avoid using the table id parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-29284

Affected Products

Multi Restaurant Table Reservation System