Impact
A flaw in the file /reviewer_0/admins/assessments/databank/btn_functions.php the ability to manipulate the ID argument causes a direct SQL injection. The flaw allows an attacker to embed arbitrary SQL commands that are executed against the database, potentially extracting sensitive data, modifying records, or deleting information. It is a classic SQL injection vulnerability that can also be grouped under non‑validated input weaknesses.
Affected Systems
The vulnerability affects SourceCodester Online Reviewer Management System version 1.0, specifically the administrative remove action within the btn_functions.php script. The system can be run on any web server provided by SourceCodester and is accessible through the web interface.
Risk and Exploitability
With a CVSS score of 6.9 the flaw is considered of moderate severity. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack can be launched remotely, and an exploit has already been published, indicating that the risk to unpatched installations is non‑negligible.
OpenCVE Enrichment