CVE-2026-36920: SQL Injection
Published Apr 13, 2026
·Updated
Sourcecodester Online Reviewer System v1.0 is vulnerable to SQL Injection in the file /system/system/admins/assessments/examproper/questions-view.php.
Affected Software
2 affected components
Sourcecodester Online Reviewer System=1.0
Janobe Online Reviewer System=1.0
Event History
Apr 13, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-36920?
The severity of CVE-2026-36920 is classified as high due to the potential for SQL injection, which can allow attackers to execute arbitrary SQL queries.
2
How do I fix CVE-2026-36920?
To fix CVE-2026-36920, sanitize and validate all user inputs in the affected file to prevent SQL injection attacks.
3
Which file is affected in CVE-2026-36920?
CVE-2026-36920 affects the file /system/system/admins/assessments/examproper/questions-view.php.
4
What software is affected by CVE-2026-36920?
CVE-2026-36920 affects Sourcecodester Online Reviewer System version 1.0.
5
What does CVE-2026-36920 allow an attacker to do?
CVE-2026-36920 allows an attacker to perform SQL injection, potentially leading to unauthorized data access or manipulation.