Impact
A vulnerability was discovered in Online Reviewer System 1.0, specifically in an undocumented function within /system/system/admins/assessments/pretest/btn_functions.php. An attacker can manipulate the difficulty_id argument, resulting in SQL injection that the system accepts and executes remotely. This flaw permits executing arbitrary SQL commands, which could lead to unauthorized reading, modification, or deletion of database data, potentially compromising confidentiality, integrity, and availability.
Affected Systems
The affected product is code-projects Online Reviewer System, version 1.0.
Risk and Exploitability
The CVSS score of 6.9 classifies the issue as moderate severity. The EPSS score of less than 1% suggests that exploitation is unlikely in the wild. The vulnerability is not listed in CISA’s KEV catalog, indicating no known large-scale exploitation. Organizations using the vulnerable version should treat the flaw as a moderate risk that could enable exploitation of the database if left unmitigated.
OpenCVE Enrichment