Description
A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown processing of the file /reviewer_0/admins/assessments/examproper/questions-view.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
Published: 2026-09-30
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection may allow unauthorized database access and data exfiltration.
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a classic SQL injection flaw in the ID argument of the questions-view.php script within the SourceCodester Online Reviewer Management System. An attacker can construct a crafted input to manipulate the query sent to the database, potentially reading, modifying, or deleting records. This can grant the attacker unauthorized access to sensitive data or disrupt the application’s integrity.

Affected Systems

SourceCodester Online Reviewer Management System version 1.0, deployed in environments using the /reviewer_0/admins/assessments/examproper/questions-view.php endpoint. The attack can be performed from any machine that reaches the exposed web interface, so the affected systems include all installations of the application that have not yet applied defensive updates.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate to high severity, with the exploitation being remote and requiring no special privileges. The EPSS score is not available, but publicly disclosed exploit code has been seen, so a realistic threat exists. The vulnerability is not currently listed in the CISA KEV catalog. Attackers could chain this flaw with other weaknesses to achieve broader compromise, making mitigation a priority.

Generated by OpenCVE AI on September 30, 2026 at 07:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the application to a patched release if one exists, or apply the vendor’s official fix when released.
  • Restrict access to the admin interface by enforcing authentication and network segmentation, ensuring only trusted hosts can reach the /reviewer_0/... endpoint.
  • Implement input validation and use parameterized queries for the ID parameter to prevent accidental manipulation of SQL commands.

Generated by OpenCVE AI on September 30, 2026 at 07:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown processing of the file /reviewer_0/admins/assessments/examproper/questions-view.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
Title SourceCodester Online Reviewer Management System questions-view.php sql injection
First Time appeared Sourcecodester
Sourcecodester online Reviewer Management System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:sourcecodester:online_reviewer_management_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester online Reviewer Management System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Online Reviewer Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-30T02:45:11.795Z

Reserved: 2026-09-29T18:08:13.768Z

Link: CVE-2026-102908

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-30T03:16:58.350

Modified: 2026-09-30T14:04:38.183

Link: CVE-2026-102908

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T07:30:17Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')