Impact
A flaw exists in the Online Reviewer System 1.0 in the studentresult-view.php component where the test_id parameter can be manipulated to inject arbitrary SQL statements. This enables an attacker to read, modify, or delete data in the underlying database, potentially exposing sensitive student records or compromising the integrity of assessment information. The weakness is an SQL injection vulnerability (CWE‑74, CWE‑89).
Affected Systems
The affected product is code-projects Online Reviewer System, version 1.0.
Risk and Exploitability
The CVSS base score is 6.9, indicating a moderate severity. The EPSS score of less than 1% suggests low but non‑zero exploitation probability, yet the vulnerability is publicly documented and could be used remotely by an attacker. It is not listed in the KEV catalog, but the presence of a public exploit raises immediate concern. The likely attack vector is remote exploitation via the web interface, requiring the ability to send crafted HTTP requests to the studentresult-view.php page.
OpenCVE Enrichment