Impact
A SQL injection flaw was identified in the SourceCodester Online Reviewer Management System. The vulnerability resides in an unspecified function of the file btn_functions.php, which processes the Subject argument. When an attacker supplies a malicious value for Subject, the application fails to sanitize the input, allowing arbitrary SQL commands to be executed against the backend database. This can lead to unauthorized data disclosure, modification, or potentially further exploitation depending on database privileges. The most direct impact is the compromise of confidential data stored by the system, and secondary impacts may include integrity violations.
Affected Systems
The affected product is SourceCodester Online Reviewer Management System, version 1.0. The flaw exists in the admin assessment module located at /reviewer_0/admins/assessments/Subject/btn_functions.php. No other versions or configurations are listed as affected.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it may not yet be actively exploited or widely known. However, the attack vector is remote and the exploit has been publicly disclosed, implying that an attacker with network access could attempt to inject malicious SQL from an external source. Given the moderate CVSS score, the vulnerability poses a reasonable risk to confidentiality and integrity of the system's data if left unmitigated. The public disclosure increases the likelihood that automated scanners may identify the target, making early remediation important.
OpenCVE Enrichment