Sceawere
Vulnerability Detail
CVE-2026-105246UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SQL Injection in Online Reviewer
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 11h ago
- Vendor
- SourceCodester
- Product
- Online Reviewer Management System
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was found in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/Subject/btn_functions.php?action=update. Performing a manipulation of the argument Subject results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-10-05T07:16:30.630Z",
"pubdate": "2026-10-05T07:16:30.630Z",
"executiveSummary": "A critical SQL injection (SQLi) vulnerability exists in the SourceCodester Online Reviewer Management System version 1.0. The vulnerability is located within the /reviewer_0/admins/assessments/Subject/btn_functions.php script, specifically affecting the 'Subject' parameter during an 'update' action.\nThis flaw allows a remote, unauthenticated or authenticated attacker to inject arbitrary SQL commands into the backend database. By manipulating the 'Subject' input, an attacker can bypass security controls, extract sensitive information, modify database records, or potentially gain unauthorized administrative access.\nGiven that the exploit is publicly available, the risk of exploitation is high. Successful execution results in a complete compromise of the application's data integrity and confidentiality. System administrators are advised to treat this as a high-priority threat.",
"technicalDetails": "The vulnerability originates from improper input sanitization and lack of parameterized queries within the 'btn_functions.php' file. The application fails to validate the 'Subject' argument before including it in a database query executed via the 'update' action.\nThe attack flow commences with the adversary sending a crafted HTTP request to the vulnerable endpoint: /reviewer_0/admins/assessments/Subject/btn_functions.php?action=update. The attacker appends malicious SQL syntax to the 'Subject' parameter. Because the application processes this input directly into a SQL statement without using prepared statements or proper escaping mechanisms, the database engine executes the attacker's injected commands.\nThe vulnerable component is the server-side script responsible for handling subject management updates. The lack of abstraction between the user input and the database query layer allows for standard SQLi exploitation patterns, such as UNION-based injection to exfiltrate data from other tables, or error-based injection to map the database structure.\nExploitation does not require advanced access if the endpoint is exposed, as the attack is initiated remotely. Once the injection is successful, the attacker can leverage the database's permissions to read, update, or delete records. If the database user configured for the application has high privileges (such as FILE or administrative rights), the attacker might further escalate their impact, potentially leading to unauthorized data dumping or modification of the application configuration.\nThe root cause is a failure to implement robust input validation and the use of dynamic string concatenation to build database queries. This is a classic injection flaw where untrusted data is interpreted as code by the backend database management system (DBMS)."
}