CVE-2026-102909: SourceCodester Online Reviewer Management System btn_functions.php sql injection
A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer0/admins/assessments/examproper/btnfunctions.php. The manipulation of the argument accesscode leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The vulnerable endpoint can be attacked remotely through the access_code argument. No authentication or user interaction is indicated in the supplied severity vector, and exploitation is described as low complexity.
Is public exploit code available?
Yes. The supplied data states that an exploit is publicly available and might be used.
Which deployment should be investigated?
Investigate SourceCodester Online Reviewer Management System version 1.0 deployments, specifically exposure of /reviewer_0/admins/assessments/examproper/btn_functions.php and its handling of the access_code parameter.