Impact
A publicly known flaw exists in the SourceCodester Online Reviewer Management System 1.0. The delete function in /reviewer_0/admins/assessments/subject/btn_functions.php can be hacked by changing the ID parameter, allowing attackers to inject arbitrary SQL commands. The resulting injection can read, modify or delete data in the underlying database, potentially exposing sensitive reviewer information or corrupting audit records. The vulnerability is classified as SQL injection, which falls under the Common Weakness Enumeration IDs 74 and 89.
Affected Systems
The affected product is SourceCodester Online Reviewer Management System version 1.0. The flaw resides in an admin endpoint that is reachable through a web interface. No other versions or components are listed as impacted according to the available vendor information.
Risk and Exploitability
The flaw carries a CVSS score of 6.9, indicating moderate to high severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified, but the publicly disclosed exploit evidence suggests it is imminently actionable. It is not currently listed in the CISA Known Exploited Vulnerabilities catalog. Attackers can trigger the vulnerability remotely by manipulating the ID argument. Successful exploitation would provide unauthorized database access, potentially leading to data breach or manipulation.
OpenCVE Enrichment