Impact
A flaw exists in the admin exam-delete.php script of code‑projects Online Reviewer System 1.0 that allows a remote attacker to manipulate the test_id parameter and inject arbitrary SQL. This flaw can be used to read, modify, or delete database records associated with exam assessments, thereby compromising data integrity and confidentiality.
Affected Systems
The vulnerability affects code‑projects Online Reviewer System version 1.0. No other versions or products were listed as impacted.
Risk and Exploitability
The flaw carries a CVSS score of 6.9, indicating moderate severity. EPSS shows less than 1 % probability of exploitation, and the issue is not currently recorded in CISA’s KEV catalog, suggesting no known widespread attacks. Nevertheless, the exploit can be launched remotely against the admin exams module, and because it targets a database operation, based on the description, it is inferred that an attacker with sufficient privileges could exfiltrate sensitive data or alter critical exam information. The potential impact is significant, especially for systems that store confidential assessment data.
OpenCVE Enrichment