Sceawere
Vulnerability Detail
CVE-2026-105182UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SQL Injection in Online Reviewer Management System
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 15h ago
- Vendor
- SourceCodester
- Product
- Online Reviewer Management System
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/activities/btn_functions.php?action=update. The manipulation of the argument Title results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-10-05T03:16:38.543Z",
"pubdate": "2026-10-05T03:16:38.543Z",
"executiveSummary": "A SQL injection vulnerability has been identified in SourceCodester Online Reviewer Management System 1.0, specifically residing within the /reviewer_0/admins/assessments/activities/btn_functions.php script. The vulnerability arises from improper neutralization of user-supplied data within the 'Title' argument during an update operation.\nThis flaw enables unauthenticated or authenticated remote attackers to inject malicious SQL commands into the application's database queries. Successful exploitation allows unauthorized parties to manipulate backend database operations, potentially resulting in unauthorized data access, modification, deletion, or complete compromise of the database integrity. Given that the exploit is publicly available, the risk of exploitation is high, and the system is susceptible to remote attacks without requiring complex conditions.",
"technicalDetails": "The vulnerability is classified as a classic SQL injection (SQLi) within the /reviewer_0/admins/assessments/activities/btn_functions.php component. The root cause is the insecure handling of the 'Title' argument when the 'action' parameter is set to 'update'. The application fails to implement adequate input validation or parameterization, allowing the 'Title' input to be concatenated directly into a database query statement.\nThe attack flow begins with the attacker sending a crafted HTTP request to the target script. By manipulating the 'Title' parameter value, an attacker can break out of the intended data context and append arbitrary SQL syntax. Because the input is not processed through prepared statements or proper escaping mechanisms, the database management system (DBMS) executes the attacker-supplied SQL commands with the privileges of the database user configured for the application.\nThe technical mechanism involves the injection of SQL operators and commands into the 'Title' field. For example, by inputting payloads containing single quotes, union operators, or comment indicators (e.g., '--'), an attacker can modify the underlying 'UPDATE' logic. This allows for unauthorized data extraction (via UNION-based injection), blind data inference (via boolean or time-based inferential techniques), or modification of records in tables that the application user can access.\nBecause this file is exposed to remote HTTP requests, the attack vector is network-based and does not require local access. The impact is significant as it affects the backend persistence layer. Once the SQL injection is successfully executed, an attacker can bypass authentication, extract sensitive administrative credentials, or dump entire database tables. If the database user possesses elevated privileges, the attacker could theoretically perform further actions such as 'stacked queries' to modify system configurations or execute OS-level commands, depending on the DBMS configuration. The availability of a public exploit simplifies the exploitation process, allowing even low-skilled actors to compromise vulnerable instances of SourceCodester Online Reviewer Management System 1.0."
}