CVE-2026-95926: SourceCodester Online Reviewer Management System btn_functions.php update sql injection
A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unknown function of the file /reviewer0/admins/assessments/pretest/btnfunctions.php?action=update. This manipulation of the argument testid causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be performed remotely and requires no privileges or user interaction according to the supplied vector. Exploitation targets the test_id argument when the update action is used.
Is public exploit information available?
Yes. The vulnerability description states that an exploit has been publicly disclosed and may be used.
How can I identify potentially affected deployments?
Identify installations of SourceCodester Online Reviewer Management System version 1.0 and review exposure of /reviewer_0/admins/assessments/pretest/btn_functions.php, particularly requests using action=update and the test_id parameter.