Junglewise Threat Intelligence

CVE-2026-93959: SourceCodester Online Reviewer Management System SQL injection

CVE-2026-93959 · Severity: high · CVSS 7.3 · Published 2026-09-20

Technologies: SourceCodester Online Reviewer Management System. Vendors: SourceCodester.

Executive brief

SourceCodester Online Reviewer Management System is a web application for managing course reviews and assessments. A SQL injection vulnerability in the course assessment module allows unauthenticated attackers to inject malicious SQL commands through the Course parameter, potentially leading to unauthorized database access, data theft, or system compromise.

Technical details

SQL injection vulnerability in /reviewer_0/admins/assessments/course/btn_functions.php (action=course) where the Course parameter is concatenated directly into SQL queries without input sanitization or prepared statements. The vulnerability is remotely exploitable without authentication and supports boolean-based blind, error-based, and time-based blind SQL injection techniques. An attacker can extract database contents, modify data, or achieve database command execution depending on backend configuration and permissions.

Affected products

  • SourceCodester Online Reviewer Management System 1.0

Timeline

  • 2026-08-23: disclosed: Vulnerability publicly disclosed on GitHub
  • 2026-09-20: advisory: CVE-2026-93959 published

References

Related threats