Description
A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/examproper/btn_functions.php. The manipulation of the argument access_code leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.
Published: 2026-09-30
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Patch Now
AI Analysis

Impact

The vulnerability resides in SourceCodester Online Reviewer Management System 1.0, where the argument access_code in the btn_functions.php file is not properly sanitized, allowing an attacker to inject arbitrary SQL queries. Because the flaw exists in a server‑side component that can be reached over the network, the attack can be launched remotely. Successful exploitation would enable a threat actor to read, modify, or delete application data, compromising data confidentiality and integrity.

Affected Systems

The affected product is SourceCodester Online Reviewer Management System version 1.0. No other versions or build numbers were identified in the official CNA data. The vulnerability applies to the /reviewer_0/admins/assessments/examproper/btn_functions.php script within that release.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity. EPSS information is not available, but the vulnerability is publicly disclosed and a functional exploit has been published, so the risk of exploitation is non‑negligible. The issue is not listed in CISA’s KEV catalogue, but the remote nature of the flaw and the use of unsanitized user input make it a significant concern for any system running the identified version.

Generated by OpenCVE AI on September 30, 2026 at 07:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any publicly released patch or update for SourceCodester Online Reviewer Management System 1.0.
  • Modify btn_functions.php to use parameterized queries or prepared statements for all database interactions involving the access_code parameter.
  • Validate the access_code input to ensure it matches the expected format or data type before it is used in a query.
  • Configure the database account used by the application to have only the minimum permissions required, preventing privileged SQL changes if injection occurs.

Generated by OpenCVE AI on September 30, 2026 at 07:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/examproper/btn_functions.php. The manipulation of the argument access_code leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.
Title SourceCodester Online Reviewer Management System btn_functions.php sql injection
First Time appeared Sourcecodester
Sourcecodester online Reviewer Management System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:sourcecodester:online_reviewer_management_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester online Reviewer Management System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Online Reviewer Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-30T13:52:48.916Z

Reserved: 2026-09-29T18:08:18.067Z

Link: CVE-2026-102909

cve-icon Vulnrichment

Updated: 2026-09-30T13:52:44.385Z

cve-icon NVD

Status : Deferred

Published: 2026-09-30T03:16:58.537

Modified: 2026-09-30T14:17:25.810

Link: CVE-2026-102909

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T07:30:17Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')