CVE-2026-2198: code-projects Online Reviewer System loaddata.php sql injection
A vulnerability was identified in code-projects Online Reviewer System 1.0. The affected element is an unknown function of the file /system/system/admins/assessments/pretest/loaddata.php. Such manipulation of the argument difficultyid leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2198?
CVE-2026-2198 is classified as a high severity SQL injection vulnerability.
How do I fix CVE-2026-2198?
To fix CVE-2026-2198, sanitize the input parameters in the loaddata.php file to prevent SQL injection.
What software is affected by CVE-2026-2198?
CVE-2026-2198 affects the code-projects Online Reviewer System version 1.0.
What type of vulnerability is CVE-2026-2198?
CVE-2026-2198 is a SQL injection vulnerability that allows attackers to execute arbitrary SQL queries.
Where is CVE-2026-2198 located in the code?
CVE-2026-2198 is located within the /system/system/admins/assessments/pretest/loaddata.php file.