CVE-2026-102908: SourceCodester Online Reviewer Management System questions-view.php sql injection
A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown processing of the file /reviewer0/admins/assessments/examproper/questions-view.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attack can be launched remotely against the affected questions-view.php endpoint by manipulating its ID argument. No authentication or user interaction is indicated by the supplied CVSS vector.
How likely is exploitation in practice?
The exploit has been publicly disclosed and may be used. The CVSS vector rates attack complexity as low, indicating exploitation does not require unusual conditions.
What security impact could successful exploitation have?
The supplied CVSS metrics indicate low impacts to confidentiality, integrity, and availability. The vulnerability is classified as SQL injection.