Sceawere
Vulnerability Detail
CVE-2026-105247UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SQL Injection in Online Reviewer
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 11h ago
- Vendor
- SourceCodester
- Product
- Online Reviewer Management System
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/Subject/btn_functions.php?action=course. Executing a manipulation of the argument Subject can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-10-05T08:17:15.020Z",
"pubdate": "2026-10-05T08:17:15.020Z",
"executiveSummary": "The SourceCodester Online Reviewer Management System 1.0 contains a critical SQL injection vulnerability within the /reviewer_0/admins/assessments/Subject/btn_functions.php file. This security flaw allows unauthenticated or remote attackers to manipulate the 'Subject' argument, facilitating unauthorized database queries. The vulnerability stems from improper neutralization of special elements used in an SQL command, which can lead to catastrophic impacts, including unauthorized data exfiltration, modification of database contents, or total compromise of the application's back-end database. Given that the exploit has been publicly disclosed, the risk of exploitation is significantly elevated. The vulnerability allows for remote execution without requiring prior authentication, making it a high-priority risk for organizations deploying this version of the Online Reviewer Management System. Compromise of the underlying database could lead to the exposure of sensitive administrative and assessment data, posing a severe threat to data integrity and confidentiality.",
"technicalDetails": "The vulnerability resides in the /reviewer_0/admins/assessments/Subject/btn_functions.php script, specifically where the 'Subject' parameter is processed via the 'action=course' request path. The application fails to implement robust input validation or parameterized queries (prepared statements) when handling the user-supplied data in the Subject argument. This oversight enables an attacker to perform SQL injection (SQLi) attacks by injecting malicious SQL fragments into the query string.\nThe exploitation flow begins when an attacker sends a crafted HTTP request to the vulnerable endpoint. By injecting SQL syntax, such as UNION-based statements or boolean-based blind injection patterns into the 'Subject' parameter, the attacker can manipulate the structure of the resulting SQL query executed by the back-end database management system. Because the input is directly concatenated into the query without prior sanitation, the interpreter treats the attacker's input as executable code rather than plain data.\nThe attack vector is remotely exploitable over HTTP/HTTPS, requiring no specific administrative privileges or session tokens to initiate. Once the malicious payload is submitted, the application executes the modified query. If the database user account used by the web application is improperly provisioned with elevated permissions, the attacker may be able to query internal system tables, extract administrative credentials, dump the contents of the entire database, or perform data manipulation tasks. In some configurations, if the database supports it, an attacker might leverage advanced SQL techniques to execute file system operations or trigger further remote code execution scenarios. The lack of parameterized query interfaces in the legacy codebase serves as the primary root cause, as the application relies on insecure string concatenation for dynamic SQL generation. This vulnerability is categorized as a failure to sanitize input, falling under the broader classification of injection vulnerabilities, which remain a persistent threat in environments where user-controlled input flows directly into database interaction logic."
}