Impact
The vulnerability exists in SourceCodester Online Reviewer Management System 1.0 within btn_functions.php. An attacker can manipulate the Course parameter in a request to the /reviewer_0/admins/assessments/course/ endpoint to inject arbitrary SQL, allowing execution of attacker‑supplied statements against the application database. This flaw permits unauthorized data exfiltration, modification, or deletion, potentially compromising confidentiality and integrity of all stored reviews and user data.
Affected Systems
The affected product is SourceCodester’s Online Reviewer Management System, version 1.0. The flaw affects the file btn_functions.php located in the admin assessments course module and any deployment that includes this exact code path.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate‑to‑high severity. Although the EPSS score is not available, the vulnerability is publicly disclosed and can be exploited remotely via the web interface. It is not listed in the CISA KEV catalog, but the presence of SQL injection without input validation poses a high exploitation risk for exposed instances. Attackers would need network access to the web server and the ability to construct a request with a malicious Course value; no privileged local access is required.
OpenCVE Enrichment