Impact
A SQL injection flaw exists in code‑projects Online Reviewer System version 1.0 within the file /reviewer/system/system/admins/manage/users/user-delete.php. Manipulating the ID parameter allows an attacker to inject arbitrary SQL statements, potentially leading to data disclosure, modification, or deletion. The vulnerability corresponds to CWE‑89 and involves improper handling of user-supplied input (CWE‑74).
Affected Systems
The affected product is code‑projects Online Reviewer System 1.0, as identified by the vendor and the common platform enumeration for the online_reviewer_system application.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. It can be initiated remotely by sending crafted HTTP requests to the vulnerable endpoint. No elevated privileges are required; any external user capable of constructing the request could potentially exploit the flaw.
OpenCVE Enrichment