CVE-2026-104123: SourceCodester Online Reviewer Management System btn_functions.php activity sql injection
A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /reviewer0/admins/assessments/activities/btnfunctions.php?action=activity. The manipulation of the argument Title results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be launched remotely and requires no privileges or user interaction according to the supplied vector. Exploitation targets the Title argument on the specified btn_functions.php activity action.
Is exploit code available?
Yes. The vulnerability data states that a public exploit exists and may be used.
What security impact could successful exploitation have?
The supplied CVSS vector indicates low impact to confidentiality, integrity, and availability. The scope is unchanged.