Sceawere
Vulnerability Detail
CVE-2026-104123UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SQL Injection in Online Reviewer
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 20h ago
- Vendor
- SourceCodester
- Product
- Online Reviewer Management System
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /reviewer_0/admins/assessments/activities/btn_functions.php?action=activity. The manipulation of the argument Title results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-10-02T03:16:39.047Z",
"pubdate": "2026-10-02T03:16:39.047Z",
"executiveSummary": "The SourceCodester Online Reviewer Management System 1.0 contains a critical SQL Injection vulnerability located within the 'btn_functions.php' file. The vulnerability exists due to improper input validation and sanitization of the 'Title' parameter when processing the 'activity' action.\nThis flaw allows a remote, unauthenticated attacker to inject malicious SQL commands into the backend database. Successful exploitation enables unauthorized access to, modification of, or destruction of sensitive data contained within the application's database, including administrative credentials or system configurations. Given the public availability of exploit code, the risk level is high. The vulnerability affects the confidentiality, integrity, and availability of the system, posing a significant risk of data exfiltration and total database compromise.",
"technicalDetails": "The vulnerability resides in the server-side handling of user-supplied data in the file /reviewer_0/admins/assessments/activities/btn_functions.php. Specifically, the 'Title' argument, which is processed during the 'activity' action, is concatenated directly into SQL queries without the use of parameterized statements or adequate input escaping. This lack of separation between code and data creates a classic SQL Injection vector.\nThe attack flow begins when an attacker sends a crafted HTTP request to the vulnerable endpoint. By supplying a specially formatted string in the 'Title' parameter, the attacker can manipulate the structure of the underlying SQL query. For instance, an attacker may inject UNION-based payloads to retrieve information from other tables in the database, or use boolean-based or time-based blind SQL injection techniques to infer the contents of the database schema.\nBecause the application fails to utilize prepared statements (e.g., PDO or MySQLi prepared statements), the database interpreter treats the injected payload as executable commands rather than literal data. This allows the attacker to bypass authentication, query arbitrary data tables, or potentially escalate privileges if the database user possesses sufficient permissions.\nThe exploitation is executable remotely and does not require pre-existing authentication, significantly increasing the attack surface. Since the exploit code is now public, automated scanning and manual exploitation are likely. Post-exploitation impact typically involves unauthorized access to sensitive user information, credentials, or personal identification information stored within the system. In some configurations, if the database service is misconfigured, an attacker might leverage database-specific functions to perform file reads or writes on the host server, potentially leading to remote code execution."
}