Sceawere
Vulnerability Detail
CVE-2026-102909UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SQL Injection in Online Reviewer
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 4h ago
- Vendor
- SourceCodester
- Product
- Online Reviewer Management System
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/examproper/btn_functions.php. The manipulation of the argument access_code leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-09-30T03:16:58.537Z",
"pubdate": "2026-09-30T03:16:58.537Z",
"executiveSummary": "A critical SQL injection vulnerability exists in the SourceCodester Online Reviewer Management System 1.0. The vulnerability resides within the /reviewer_0/admins/assessments/examproper/btn_functions.php file, specifically targeting the 'access_code' argument.\nThis flaw allows remote, unauthenticated attackers to manipulate database queries by injecting malicious SQL commands into the application's backend. The impact of this vulnerability is severe, potentially resulting in unauthorized data exfiltration, modification of database contents, or complete compromise of the underlying database server.\nThe risk is exacerbated by the availability of public exploits, increasing the likelihood of successful exploitation by malicious actors. Organizations using this software are at significant risk of data breaches and service disruption. Immediate remediation is required to sanitize input parameters and prevent unauthorized database interaction.",
"technicalDetails": "The vulnerability is a classic SQL injection flaw stemming from improper neutralization of user-supplied input within the /reviewer_0/admins/assessments/examproper/btn_functions.php file of the SourceCodester Online Reviewer Management System 1.0. The application fails to adequately sanitize or parameterize the 'access_code' argument before incorporating it into an active database query.\nThe root cause is the reliance on dynamic query construction where user-provided input is concatenated directly into SQL statements. When an attacker submits a crafted string via the 'access_code' parameter, they can break the intended logic of the SQL statement, allowing the injection of arbitrary SQL commands.\nThe attack flow begins with a remote attacker identifying the entry point, the 'access_code' argument processed by the vulnerable PHP script. By injecting SQL syntax (such as UNION SELECT statements or boolean-based blind injection payloads), the attacker can force the database to execute commands beyond its original design.\nBecause this file is exposed to the web, the exploit can be initiated remotely without the requirement for prior authentication or elevated administrative privileges in some configurations. Once the payload is successfully executed, the database interpreter parses the malicious input, which may lead to unauthorized access to the entire database schema.\nPost-exploitation impact includes the ability to bypass authentication, extract sensitive information from the database (such as user credentials, assessment data, or system configuration), modify or delete records, and in certain misconfigured database environments, achieve remote code execution via administrative database functions like 'xp_cmdshell' or file read/write operations.\nThe availability of public exploit code lowers the barrier to entry, enabling attackers to perform automated scans and exploitation of this flaw. The lack of parameterized queries or prepared statements in the affected component makes it highly susceptible to these types of injection attacks."
}