Sceawere

Vulnerability Detail

CVE-2026-102910UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SQL Injection in Online Reviewer

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
3h ago
Vendor
SourceCodester
Product
Online Reviewer Management System
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/examproper/exam-delete.php. The manipulation of the argument test_id results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-09-30T04:18:27.613Z",
  "pubdate": "2026-09-30T04:18:27.613Z",
  "executiveSummary": "A critical SQL injection vulnerability has been identified in the SourceCodester Online Reviewer Management System version 1.0. The vulnerability resides within the exam-delete.php file, specifically affecting the processing of the test_id parameter.\nThis flaw allows remote, unauthenticated, or authenticated attackers to manipulate backend database queries by injecting malicious SQL commands into the input field. Successful exploitation of this vulnerability permits unauthorized access to the underlying database, enabling attackers to extract sensitive information, modify data, or potentially perform administrative operations.\nThe risk is severe as the vulnerability can be exploited remotely, and public availability of exploit code increases the likelihood of active targeting. Organizations utilizing this software are at significant risk of data breaches and integrity loss. Remediation requires immediate intervention to sanitize user input and implement robust database interaction practices.",
  "technicalDetails": "The vulnerability is categorized as a classic SQL Injection (SQLi), stemming from the improper neutralization of special elements used in an SQL command within the file /reviewer_0/admins/assessments/examproper/exam-delete.php.\nThe root cause is the failure of the application to properly sanitize or parameterize the 'test_id' argument before incorporating it into a database query. When a user supplies input via the test_id parameter, the application directly concatenates this input into the SQL string executed by the database management system.\nThe attack flow proceeds as follows: An attacker sends a crafted HTTP request to the vulnerable endpoint /reviewer_0/admins/assessments/examproper/exam-delete.php. The 'test_id' parameter is manipulated by injecting malicious SQL syntax, such as UNION-based statements or boolean-based blind injection payloads. Because the application logic lacks adequate input validation or the use of prepared statements (parameterized queries), the injected SQL code is parsed and executed by the backend database.\nBy leveraging this flaw, an attacker can bypass existing authentication or authorization mechanisms to access protected data. Furthermore, the attacker may be able to gain full administrative control over the database, including the extraction of user credentials, system configurations, and sensitive records stored within the application's schema. The impact is significant, as it leads to full confidentiality, integrity, and availability compromise of the database environment.\nThe vulnerability is considered remotely exploitable, requiring no complex interaction beyond sending the specifically crafted request to the web server. Since public exploit code exists, the effort required to weaponize this vulnerability is minimal, making it an attractive target for automated scanning and manual exploitation by malicious actors."
}
CVE-2026-102910: SQL Injection in Online Reviewer (HIGH Severity, CVSS: 7.3) | Sceawere