Impact
The vulnerability resides in SourceCodester Online Reviewer Management System 1.0, where the argument access_code in the btn_functions.php file is not properly sanitized, allowing an attacker to inject arbitrary SQL queries. Because the flaw exists in a server‑side component that can be reached over the network, the attack can be launched remotely. Successful exploitation would enable a threat actor to read, modify, or delete application data, compromising data confidentiality and integrity.
Affected Systems
The affected product is SourceCodester Online Reviewer Management System version 1.0. No other versions or build numbers were identified in the official CNA data. The vulnerability applies to the /reviewer_0/admins/assessments/examproper/btn_functions.php script within that release.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. EPSS information is not available, but the vulnerability is publicly disclosed and a functional exploit has been published, so the risk of exploitation is non‑negligible. The issue is not listed in CISA’s KEV catalogue, but the remote nature of the flaw and the use of unsanitized user input make it a significant concern for any system running the identified version.
OpenCVE Enrichment