Junglewise Threat Intelligence

CVE-2026-95924: SourceCodester Online Reviewer Management System SQL injection in btn_functions.php

CVE-2026-95924 · Severity: high · CVSS 7.3 · Published 2026-09-23

Technologies: SourceCodester Online Reviewer Management System. Vendors: SourceCodester.

Executive brief

SourceCodester Online Reviewer Management System is a web-based application for managing exam reviews and assessments. A SQL injection vulnerability in the question submission function allows unauthenticated attackers to manipulate database queries by injecting malicious code through the difficulty_id parameter, enabling unauthorized access to sensitive data, database modification, or complete system compromise.

Technical details

A boolean-based blind SQL injection vulnerability exists in /reviewer_0/admins/assessments/databank/btn_functions.php (action=add) where the difficulty_id POST parameter is directly concatenated into SQL queries without sanitization or prepared statements. The vulnerability is accessible without authentication and can be exploited remotely using standard SQL injection techniques (e.g., sqlmap). Successful exploitation grants attackers unauthorized database access, data exfiltration, data modification, and potential remote code execution depending on database permissions.

Affected products

  • SourceCodester Online Reviewer Management System 1.0

Timeline

  • 2026-08-30: disclosed: Vulnerability disclosed on GitHub
  • 2026-09-23: advisory: Published as CVE-2026-95924

References

Related threats