Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9fgh-6w4g-5r53

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The file view-chair-list.php in Multi Restaurant Table Reservation System 1.0 does not perform input validation on the table_id parameter which allows unauthenticated SQL Injection. An attacker can send malicious input in the GET request to /dashboard/view-chair-list.php?table_id= to trigger the vulnerability.

The file view-chair-list.php in Multi Restaurant Table Reservation System 1.0 does not perform input validation on the table_id parameter which allows unauthenticated SQL Injection. An attacker can send malicious input in the GET request to /dashboard/view-chair-list.php?table_id= to trigger the vulnerability.

EPSS

Процентиль: 96%
0.21285
Средний

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
около 5 лет назад

The file view-chair-list.php in Multi Restaurant Table Reservation System 1.0 does not perform input validation on the table_id parameter which allows unauthenticated SQL Injection. An attacker can send malicious input in the GET request to /dashboard/view-chair-list.php?table_id= to trigger the vulnerability.

EPSS

Процентиль: 96%
0.21285
Средний

Дефекты

CWE-89