Impact
The vulnerability resides in the exam-delete.php file of the SourceCodester Online Reviewer Management System 1.0, where an unvalidated test_id parameter permits arbitrary SQL commands to be injected. This SQL injection flaw can lead to unauthorized reading, modification, or deletion of database records, jeopardizing the confidentiality, integrity, and availability of the application’s data. The flaw is associated with CWE-74 (Improper Handling of SQL Statements) and CWE-89 (SQL Injection).
Affected Systems
SourceCodester’s Online Reviewer Management System version 1.0 is affected. No other versions are listed as impacted, and the vendor is SourceCodester. The vulnerability affects the admin functionality located at /reviewer_0/admins/assessments/examproper/exam-delete.php.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity. EPSS is not available, and the vulnerability is not yet listed in CISA’s KEV catalog. The attack vector is remote, as the exploit can be triggered over a network. Publicly available exploit code shows that attackers can manipulate test_id to execute arbitrary SQL statements, which may give them elevated privileges or allow data exfiltration.
OpenCVE Enrichment