Impact
The vulnerability is a classic SQL injection flaw in the ID argument of the questions-view.php script within the SourceCodester Online Reviewer Management System. An attacker can construct a crafted input to manipulate the query sent to the database, potentially reading, modifying, or deleting records. This can grant the attacker unauthorized access to sensitive data or disrupt the application’s integrity.
Affected Systems
SourceCodester Online Reviewer Management System version 1.0, deployed in environments using the /reviewer_0/admins/assessments/examproper/questions-view.php endpoint. The attack can be performed from any machine that reaches the exposed web interface, so the affected systems include all installations of the application that have not yet applied defensive updates.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate to high severity, with the exploitation being remote and requiring no special privileges. The EPSS score is not available, but publicly disclosed exploit code has been seen, so a realistic threat exists. The vulnerability is not currently listed in the CISA KEV catalog. Attackers could chain this flaw with other weaknesses to achieve broader compromise, making mitigation a priority.
OpenCVE Enrichment