CVE-2026-95925: SourceCodester Online Reviewer Management System btn_functions.php update sql injection
Published Sep 23, 2026
·Updated
A vulnerability was found in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer0/admins/assessments/databank/btnfunctions.php?action=update. The manipulation of the argument difficultyid results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
Affected Software
1 affected component
Sourcecodester Online Reviewer Management System=1.0
Event History
Sep 23, 2026
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require authentication or user interaction?
No authentication or user interaction is indicated. The issue can be exploited remotely with low attack complexity by manipulating the difficulty_id argument.
2
Is public exploit code available?
Yes. The available information states that an exploit has been made public and could be used.