Sceawere

Vulnerability Detail

CVE-2026-102909UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SQL Injection in Online Reviewer

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
4h ago
Vendor
SourceCodester
Product
Online Reviewer Management System
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/examproper/btn_functions.php. The manipulation of the argument access_code leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-09-30T03:16:58.537Z",
  "pubdate": "2026-09-30T03:16:58.537Z",
  "executiveSummary": "A critical SQL injection vulnerability exists in the SourceCodester Online Reviewer Management System 1.0. The vulnerability resides within the /reviewer_0/admins/assessments/examproper/btn_functions.php file, specifically targeting the 'access_code' argument.\nThis flaw allows remote, unauthenticated attackers to manipulate database queries by injecting malicious SQL commands into the application's backend. The impact of this vulnerability is severe, potentially resulting in unauthorized data exfiltration, modification of database contents, or complete compromise of the underlying database server.\nThe risk is exacerbated by the availability of public exploits, increasing the likelihood of successful exploitation by malicious actors. Organizations using this software are at significant risk of data breaches and service disruption. Immediate remediation is required to sanitize input parameters and prevent unauthorized database interaction.",
  "technicalDetails": "The vulnerability is a classic SQL injection flaw stemming from improper neutralization of user-supplied input within the /reviewer_0/admins/assessments/examproper/btn_functions.php file of the SourceCodester Online Reviewer Management System 1.0. The application fails to adequately sanitize or parameterize the 'access_code' argument before incorporating it into an active database query.\nThe root cause is the reliance on dynamic query construction where user-provided input is concatenated directly into SQL statements. When an attacker submits a crafted string via the 'access_code' parameter, they can break the intended logic of the SQL statement, allowing the injection of arbitrary SQL commands.\nThe attack flow begins with a remote attacker identifying the entry point, the 'access_code' argument processed by the vulnerable PHP script. By injecting SQL syntax (such as UNION SELECT statements or boolean-based blind injection payloads), the attacker can force the database to execute commands beyond its original design.\nBecause this file is exposed to the web, the exploit can be initiated remotely without the requirement for prior authentication or elevated administrative privileges in some configurations. Once the payload is successfully executed, the database interpreter parses the malicious input, which may lead to unauthorized access to the entire database schema.\nPost-exploitation impact includes the ability to bypass authentication, extract sensitive information from the database (such as user credentials, assessment data, or system configuration), modify or delete records, and in certain misconfigured database environments, achieve remote code execution via administrative database functions like 'xp_cmdshell' or file read/write operations.\nThe availability of public exploit code lowers the barrier to entry, enabling attackers to perform automated scans and exploitation of this flaw. The lack of parameterized queries or prepared statements in the affected component makes it highly susceptible to these types of injection attacks."
}
CVE-2026-102909: SQL Injection in Online Reviewer (HIGH Severity, CVSS: 7.3) | Sceawere