Executive brief
SourceCodester Online Reviewer Management System is a PHP-based web application for managing student assessments and reviews. A SQL injection vulnerability in the assessment pretest module allows unauthenticated attackers to manipulate the test_id parameter and execute arbitrary database queries, potentially exposing, modifying, or deleting sensitive student and test data.
Technical details
A SQL injection vulnerability exists in /reviewer_0/admins/assessments/pretest/btn_functions.php where the test_id parameter is concatenated directly into SQL queries without input validation or prepared statements. The vulnerability is reachable via POST requests without authentication and supports multiple SQL injection techniques including boolean-based blind, error-based, and time-based blind attacks. Exploitation permits unauthorized database access, data theft, modification, and potential system compromise.
Affected products
- SourceCodester Online Reviewer Management System 1.0
Timeline
- 2026-08-30: disclosed: Publicly disclosed on GitHub with POC
- 2026-09-23: advisory: CVE assigned and published to NVD