CVE-2026-102910: SourceCodester Online Reviewer Management System exam-delete.php sql injection
A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer0/admins/assessments/examproper/exam-delete.php. The manipulation of the argument testid results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be launched remotely and requires no privileges or user interaction according to the supplied severity vector. Exploitation targets the test_id argument handled by /reviewer_0/admins/assessments/examproper/exam-delete.php.
Is public exploit code available?
Yes. The available data states that an exploit has been released publicly and may be used in attacks.
What impact is indicated by the available assessment?
The severity vector indicates low impacts to confidentiality, integrity, and availability. The overall severity is rated high with a score of 7.3.