Description
A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/Subject/btn_functions.php?action=course. Executing a manipulation of the argument Subject can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Published: 2026-10-05
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data Compromise via SQL Injection
Action: Apply Patch
AI Analysis

Impact

A SQL injection flaw was identified in the SourceCodester Online Reviewer Management System. The vulnerability resides in an unspecified function of the file btn_functions.php, which processes the Subject argument. When an attacker supplies a malicious value for Subject, the application fails to sanitize the input, allowing arbitrary SQL commands to be executed against the backend database. This can lead to unauthorized data disclosure, modification, or potentially further exploitation depending on database privileges. The most direct impact is the compromise of confidential data stored by the system, and secondary impacts may include integrity violations.

Affected Systems

The affected product is SourceCodester Online Reviewer Management System, version 1.0. The flaw exists in the admin assessment module located at /reviewer_0/admins/assessments/Subject/btn_functions.php. No other versions or configurations are listed as affected.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it may not yet be actively exploited or widely known. However, the attack vector is remote and the exploit has been publicly disclosed, implying that an attacker with network access could attempt to inject malicious SQL from an external source. Given the moderate CVSS score, the vulnerability poses a reasonable risk to confidentiality and integrity of the system's data if left unmitigated. The public disclosure increases the likelihood that automated scanners may identify the target, making early remediation important.

Generated by OpenCVE AI on October 5, 2026 at 08:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor’s security patch that addresses the SQL injection in the btn_functions.php endpoint of SourceCodester Online Reviewer Management System 1.0.
  • If a patch is not yet available, limit access to the /reviewer_0/admins/assessments/Subject/btn_functions.php URL and implement strict input validation to ensure the Subject parameter is properly sanitized before being used in database queries.
  • Monitor application and database logs for anomalous query patterns and verify that database credentials are stored securely and monitored for unauthorized use.

Generated by OpenCVE AI on October 5, 2026 at 08:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 07:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/Subject/btn_functions.php?action=course. Executing a manipulation of the argument Subject can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Title SourceCodester Online Reviewer Management System btn_functions.php course sql injection
First Time appeared Sourcecodester
Sourcecodester online Reviewer Management System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:sourcecodester:online_reviewer_management_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester online Reviewer Management System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Online Reviewer Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-05T15:29:55.762Z

Reserved: 2026-10-04T16:32:25.272Z

Link: CVE-2026-105247

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T08:17:15.020

Modified: 2026-10-05T08:17:15.020

Link: CVE-2026-105247

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T08:45:07Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')