CVE-2026-105246: SourceCodester Online Reviewer Management System btn_functions.php update sql injection
A vulnerability was found in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer0/admins/assessments/Subject/btnfunctions.php?action=update. Performing a manipulation of the argument Subject results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Instances of SourceCodester Online Reviewer Management System 1.0 that expose the affected admin assessment endpoint are potentially exposed. The attack can be initiated remotely, and no authentication requirement is stated in the available data.
What does an attacker need to exploit it?
An attacker needs to send a request to /reviewer_0/admins/assessments/Subject/btn_functions.php?action=update with a manipulated Subject argument. The available data identifies SQL injection in that parameter and notes that public exploit code exists.
Is there a public exploit available?
Yes. The exploit has been made public and could be used.
How can I determine whether my deployment is affected?
Verify whether the deployment is SourceCodester Online Reviewer Management System version 1.0 and whether the specified btn_functions.php update action is present. Test or review handling of the Subject argument for the affected request path in a controlled manner.