Executive brief
SourceCodester Online Reviewer Management System is a web-based platform for managing code review assessments. An SQL injection vulnerability in the assessment question update function allows remote attackers to execute arbitrary database queries, potentially exposing or modifying sensitive review data and system information without authentication.
Technical details
A boolean-based blind SQL injection exists in the difficulty_id parameter of /reviewer_0/admins/assessments/databank/btn_functions.php?action=update due to insufficient input validation and lack of parameterized queries. The vulnerability is network-accessible and requires no authentication. Successful exploitation grants attackers read/write access to the underlying database, enabling data exfiltration, manipulation, or service disruption.
Affected products
- SourceCodester Online Reviewer Management System 1.0
Timeline
- 2026-08-30: disclosed
- 2026-09-23: advisory