Junglewise Threat Intelligence

CVE-2026-95927: SourceCodester Online Reviewer Management System SQL injection

CVE-2026-95927 · Severity: high · CVSS 7.3 · Published 2026-09-23

Technologies: SourceCodester Online Reviewer Management System. Vendors: SourceCodester.

Executive brief

SourceCodester Online Reviewer Management System is a PHP web application for managing code reviews and exams. A SQL injection vulnerability in the exam deletion function allows remote attackers to bypass authentication and manipulate the database, leading to unauthorized data access, modification, or deletion without requiring login credentials.

Technical details

A SQL injection vulnerability exists in /reviewer_0/admins/assessments/pretest/exam-delete.php where the test_id parameter is directly interpolated into SQL queries without sanitization or parameterized statements. The vulnerability is unauthenticated and remotely exploitable via GET requests, allowing attackers to execute arbitrary SQL queries to read, modify, or delete database contents. Exploitation techniques include boolean-based blind, error-based, stacked queries, and time-based blind SQL injection.

Affected products

  • SourceCodester Online Reviewer Management System 1.0

Timeline

  • 2026-09-23: disclosed: Vulnerability disclosed and CVE-2026-95927 assigned

References

Related threats