Description
A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown processing of the file /reviewer_0/admins/assessments/course/btn_functions.php. This manipulation of the argument Course causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Published: 2026-09-20
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Apply Patch
AI Analysis

Impact

The vulnerability exists in SourceCodester Online Reviewer Management System 1.0 within btn_functions.php. An attacker can manipulate the Course parameter in a request to the /reviewer_0/admins/assessments/course/ endpoint to inject arbitrary SQL, allowing execution of attacker‑supplied statements against the application database. This flaw permits unauthorized data exfiltration, modification, or deletion, potentially compromising confidentiality and integrity of all stored reviews and user data.

Affected Systems

The affected product is SourceCodester’s Online Reviewer Management System, version 1.0. The flaw affects the file btn_functions.php located in the admin assessments course module and any deployment that includes this exact code path.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate‑to‑high severity. Although the EPSS score is not available, the vulnerability is publicly disclosed and can be exploited remotely via the web interface. It is not listed in the CISA KEV catalog, but the presence of SQL injection without input validation poses a high exploitation risk for exposed instances. Attackers would need network access to the web server and the ability to construct a request with a malicious Course value; no privileged local access is required.

Generated by OpenCVE AI on September 20, 2026 at 03:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update SourceCodester Online Reviewer Management System to the latest version that contains the fix
  • Modify Course parameter handling to use prepared statements or sanitize input to prevent SQL injection
  • Restrict access to the /reviewer_0/admins/assessments/course/ endpoint by enforcing authentication and role‑based access control
  • Deploy a web application firewall to detect and block malformed SQL queries

Generated by OpenCVE AI on September 20, 2026 at 03:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown processing of the file /reviewer_0/admins/assessments/course/btn_functions.php. This manipulation of the argument Course causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Title SourceCodester Online Reviewer Management System btn_functions.php sql injection
First Time appeared Sourcecodester
Sourcecodester online Reviewer Management System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:sourcecodester:online_reviewer_management_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester online Reviewer Management System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Online Reviewer Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-22T17:45:21.128Z

Reserved: 2026-09-19T09:14:44.919Z

Link: CVE-2026-93959

cve-icon Vulnrichment

Updated: 2026-09-22T17:25:23.993Z

cve-icon NVD

Status : Deferred

Published: 2026-09-20T03:16:31.513

Modified: 2026-09-22T18:17:31.647

Link: CVE-2026-93959

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-26T20:30:02Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')