Description
A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/examproper/exam-delete.php. The manipulation of the argument test_id results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Published: 2026-09-30
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL injection allowing unauthorized data access and potential privilege escalation
Action: Patch
AI Analysis

Impact

The vulnerability resides in the exam-delete.php file of the SourceCodester Online Reviewer Management System 1.0, where an unvalidated test_id parameter permits arbitrary SQL commands to be injected. This SQL injection flaw can lead to unauthorized reading, modification, or deletion of database records, jeopardizing the confidentiality, integrity, and availability of the application’s data. The flaw is associated with CWE-74 (Improper Handling of SQL Statements) and CWE-89 (SQL Injection).

Affected Systems

SourceCodester’s Online Reviewer Management System version 1.0 is affected. No other versions are listed as impacted, and the vendor is SourceCodester. The vulnerability affects the admin functionality located at /reviewer_0/admins/assessments/examproper/exam-delete.php.

Risk and Exploitability

The CVSS score of 6.9 indicates medium severity. EPSS is not available, and the vulnerability is not yet listed in CISA’s KEV catalog. The attack vector is remote, as the exploit can be triggered over a network. Publicly available exploit code shows that attackers can manipulate test_id to execute arbitrary SQL statements, which may give them elevated privileges or allow data exfiltration.

Generated by OpenCVE AI on September 30, 2026 at 06:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a patched version of SourceCodester Online Reviewer Management System once the vendor publishes an update that removes the SQL injection vulnerability.
  • Restrict the database user used by the application to the minimum privileges required for normal operation, preventing injected queries from altering or deleting data.
  • Implement input validation or prepared statements for the test_id parameter to eliminate the possibility of injected SQL being executed.
  • Deploy a web application firewall rule set that detects and blocks SQL injection attempts targeting the exam-delete.php endpoint.

Generated by OpenCVE AI on September 30, 2026 at 06:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/examproper/exam-delete.php. The manipulation of the argument test_id results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Title SourceCodester Online Reviewer Management System exam-delete.php sql injection
First Time appeared Sourcecodester
Sourcecodester online Reviewer Management System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:sourcecodester:online_reviewer_management_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester online Reviewer Management System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Online Reviewer Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-30T03:30:07.440Z

Reserved: 2026-09-29T18:08:21.518Z

Link: CVE-2026-102910

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-30T04:18:27.613

Modified: 2026-09-30T14:04:38.183

Link: CVE-2026-102910

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T06:45:13Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')