Impact
A known SQL injection flaw exists in the Unknown function of /reviewer_0/admins/assessments/course/btn_functions.php in SourceCodester Online Reviewer Management System. The flaw arises when an attacker manipulates the courseID argument, which can be used to inject arbitrary SQL statements. This weakness is classified as CWE-74 (Improper Validation of Data Structures) and CWE-89 (SQL Injection). A successful exploitation permits an attacker to read sensitive data from the database or modify records, compromising confidentiality and integrity.
Affected Systems
The vulnerability is present in SourceCodester Online Reviewer Management System version 1.0. No other versions are mentioned in the data.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the EPSS score is not available. The exploit is noted as remote and publicly disclosed, but it is not listed in the CISA KEV catalog. The attack can be carried out via the web interface by manipulating the courseID parameter, with no special privilege or local access required. Given the moderate CVSS and lack of known mitigations in the public domain, the likelihood of exploitation remains unclear but should be treated with caution.
OpenCVE Enrichment