Description
A vulnerability was found in SourceCodester Online Reviewer System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /reviewer/system/system/admins/manage/users/user-update.php of the component GET Parameter Handler. The manipulation of the argument user_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-228398 is the identifier assigned to this vulnerability.
Published: 2023-05-09
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-34070 A vulnerability was found in SourceCodester Online Reviewer System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /reviewer/system/system/admins/manage/users/user-update.php of the component GET Parameter Handler. The manipulation of the argument user_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-228398 is the identifier assigned to this vulnerability.
History

Tue, 14 Apr 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Janobe
Janobe online Reviewer System
CPEs cpe:2.3:a:online_reviewer_system_project:online_reviewer_system:1.0:*:*:*:*:*:*:* cpe:2.3:a:janobe:online_reviewer_system:1.0:*:*:*:*:*:*:*
Vendors & Products Online Reviewer System Project
Online Reviewer System Project online Reviewer System
Janobe
Janobe online Reviewer System

Subscriptions

Janobe Online Reviewer System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2024-08-02T06:26:09.825Z

Reserved: 2023-05-09T12:16:25.948Z

Link: CVE-2023-2596

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-05-09T13:15:18.043

Modified: 2026-04-14T21:32:01.427

Link: CVE-2023-2596

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses