CVE-2026-93972: SourceCodester Online Reviewer Management System btn_functions.php sql injection
A security vulnerability has been detected in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer0/admins/assessments/course/btnfunctions.php. Such manipulation of the argument courseID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability can be exploited remotely and requires no privileges or user interaction, according to the supplied vector. Public exploit disclosure increases the likelihood of exploitation attempts.
What input and component are affected?
The affected input is the courseID argument handled by /reviewer_0/admins/assessments/course/btn_functions.php. Manipulating this argument can lead to SQL injection.
What impact could successful exploitation have?
The provided severity vector indicates low impacts to confidentiality, integrity, and availability. The vulnerability is rated high with a CVSS score of 7.3.