Sceawere
Vulnerability Detail
CVE-2026-102908UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SQL Injection in Online Reviewer
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 4h ago
- Vendor
- SourceCodester
- Product
- Online Reviewer Management System
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown processing of the file /reviewer_0/admins/assessments/examproper/questions-view.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-09-30T03:16:58.350Z",
"pubdate": "2026-09-30T03:16:58.350Z",
"executiveSummary": "The SourceCodester Online Reviewer Management System 1.0 contains a critical SQL injection vulnerability within the /reviewer_0/admins/assessments/examproper/questions-view.php file.\nThis vulnerability allows an unauthenticated or remote attacker to manipulate the ID argument, facilitating unauthorized database interaction.\nThe root cause is improper sanitization of user-supplied input, enabling the injection of malicious SQL queries.\nExploitation of this flaw grants an attacker the ability to bypass security controls, extract sensitive information from the application backend, or manipulate existing data records.\nGiven that the exploit is publicly disclosed, the risk of automated or manual exploitation is significant, potentially leading to a complete compromise of the database integrity and confidentiality.\nAccess to the vulnerability is achieved via the network, allowing remote execution without complex prerequisites, making it a high-priority security concern for deployments utilizing this software.",
"technicalDetails": "The vulnerability resides in the questions-view.php script, located within the /reviewer_0/admins/assessments/examproper/ directory. The application fails to adequately validate and sanitize the ID parameter before concatenating it into a SQL query string.\nThe attack vector involves a standard SQL injection technique where the attacker crafts a malicious payload in place of the expected integer ID value. By injecting SQL syntax characters such as single quotes ('), comment operators (--), or UNION statements, the attacker can alter the query's original logic.\nThe attack flow begins when an attacker sends an HTTP GET or POST request to the target script, injecting the malicious string into the ID parameter. Because the server-side code executes this string directly against the database management system, the database interprets the attacker's input as executable code rather than a literal value.\nThe exploitation process typically involves: 1) Probing the application to determine the database structure via UNION-based or error-based techniques. 2) Identifying the number of columns and data types in the target table. 3) Extracting database metadata, table names, and user credentials. 4) Exfiltrating sensitive content stored within the application's database.\nBecause the vulnerable file resides in the administrative assessment management module, the successful injection could potentially expose administrative sessions or question banks, facilitating unauthorized modification of exam parameters or administrative data leakage.\nThe lack of prepared statements or parameterized queries in the affected component constitutes the primary root cause. Since the application does not utilize an abstraction layer to isolate user input from the query structure, it remains susceptible to direct command injection. Post-exploitation impact is severe, as it grants the attacker unauthorized read/write access to the application's backend database, potentially leading to administrative account takeover or total data exfiltration."
}