Sceawere
Vulnerability Detail
CVE-2026-102910UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SQL Injection in Online Reviewer
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 3h ago
- Vendor
- SourceCodester
- Product
- Online Reviewer Management System
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/examproper/exam-delete.php. The manipulation of the argument test_id results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-09-30T04:18:27.613Z",
"pubdate": "2026-09-30T04:18:27.613Z",
"executiveSummary": "A critical SQL injection vulnerability has been identified in the SourceCodester Online Reviewer Management System version 1.0. The vulnerability resides within the exam-delete.php file, specifically affecting the processing of the test_id parameter.\nThis flaw allows remote, unauthenticated, or authenticated attackers to manipulate backend database queries by injecting malicious SQL commands into the input field. Successful exploitation of this vulnerability permits unauthorized access to the underlying database, enabling attackers to extract sensitive information, modify data, or potentially perform administrative operations.\nThe risk is severe as the vulnerability can be exploited remotely, and public availability of exploit code increases the likelihood of active targeting. Organizations utilizing this software are at significant risk of data breaches and integrity loss. Remediation requires immediate intervention to sanitize user input and implement robust database interaction practices.",
"technicalDetails": "The vulnerability is categorized as a classic SQL Injection (SQLi), stemming from the improper neutralization of special elements used in an SQL command within the file /reviewer_0/admins/assessments/examproper/exam-delete.php.\nThe root cause is the failure of the application to properly sanitize or parameterize the 'test_id' argument before incorporating it into a database query. When a user supplies input via the test_id parameter, the application directly concatenates this input into the SQL string executed by the database management system.\nThe attack flow proceeds as follows: An attacker sends a crafted HTTP request to the vulnerable endpoint /reviewer_0/admins/assessments/examproper/exam-delete.php. The 'test_id' parameter is manipulated by injecting malicious SQL syntax, such as UNION-based statements or boolean-based blind injection payloads. Because the application logic lacks adequate input validation or the use of prepared statements (parameterized queries), the injected SQL code is parsed and executed by the backend database.\nBy leveraging this flaw, an attacker can bypass existing authentication or authorization mechanisms to access protected data. Furthermore, the attacker may be able to gain full administrative control over the database, including the extraction of user credentials, system configurations, and sensitive records stored within the application's schema. The impact is significant, as it leads to full confidentiality, integrity, and availability compromise of the database environment.\nThe vulnerability is considered remotely exploitable, requiring no complex interaction beyond sending the specifically crafted request to the web server. Since public exploit code exists, the effort required to weaponize this vulnerability is minimal, making it an attractive target for automated scanning and manual exploitation by malicious actors."
}