Impact
A SQL injection flaw exists in the exam-delete.php script of SourceCodester Online Reviewer Management System 1.0. The flaw is caused by inadequate sanitization of the test_id parameter, allowing an attacker to inject arbitrary SQL statements. The vulnerability is classified as CWE‑74 and CWE‑89 and can compromise the confidentiality, integrity, and availability of the underlying database by enabling the extraction, modification, or deletion of data.
Affected Systems
The system affected is SourceCodester’s Online Reviewer Management System, version 1.0. The vulnerability resides in the admin assessment pretest exam-delete.php module on that release. No additional affected versions are listed, so the risk applies to installations running 1.0.
Risk and Exploitability
The flaw carries a CVSS base score of 6.9, indicating a moderate severity level. Remote exploitation is possible and an exploit is publicly available, but the EPSS score is not published. The vulnerability is not yet listed in the CISA KEV catalog. Because of the public availability of the exploit and the remote nature of the attack vector, the likelihood of exploitation is non‑negligible, especially for unattended or unpatched deployments.
OpenCVE Enrichment