HomeSecuritySourceCodester Online Reviewer: Four SQL injection vulnerabilities

SourceCodester Online Reviewer: Four SQL injection vulnerabilities

Four SQL injection vulnerabilities have been identified in SourceCodester Online Reviewer Management System 1.0, an application used to manage online exams. The CVE entries describe remote exploitation without privileges and public disclosure of technical details.

SourceCodester Online Reviewer vulnerabilities

The issue concerns the system and four different parts of the management code. Entries CVE-2026-95924 and CVE-2026-95925 relate to the difficulty_id, while CVE-2026-95926 and CVE-2026-95927 relate to the test_id field.

This particular application is an open source project often found in educational environments and small facilities, where the administrative interface may remain accessible from the internet. This increases the importance of proper segmentation, even when the system does not host particularly sensitive data.

See also: CVE-2026-90526: SQL injection in School Registration and Fee System

What do vulnerabilities mean in SourceCodester Online Reviewer?

According to the CVE Feed entries, the first two vulnerabilities are located in /reviewer_0/admins/assessments/databank/btn_functions.php. One is triggered in the add and the other in the update, when the server processes the difficulty_id without adequate protection.

The other two vulnerabilities are located in /reviewer_0/admins/assessments/pretest/btn_functions.php and concern updating or deleting a test via the test_id. The description of CVE-2026-95926 and CVE-2026-95927 mentions remote attack and publicly available exploits.

In practice, a SQL injection at this level can allow manipulation of queries executed by the application on the database. The exact result depends on the permissions of the database account, the server configuration, and the additional filters applied by each installation. For this reason, the CVSS score should not be considered a complete assessment of the operational risk.

SQL injection in SourceCodester Online Reviewer

High rating and public disclosure

The entries for CVE-2026-95924 through CVE-2026-95927 are given a CVSS 3.1 score of 7.3, which is considered high severity. The common picture is a network attack, low complexity, no required privileges, and zero user interaction. In CVSS 4.0, the same vulnerabilities appear with a lower numerical score because a different scoring methodology is used.

A reference to a publicly disclosed exploit does not equate to a confirmed exploit in real installations. So far, the available listings document the technical description and publication of the data, not a specific attack campaign or incident in an organization.

Administrators should not rely solely on the CVSS score. A combination of auditing logs, restricting access, and ensuring that the database is running with the minimum necessary privileges is useful. Since the application is used for exams, the integrity of data related to subjects, grades, and accounts should also be checked.

See also: CVE-2026-19899 SourceCodester: Critical SQL injection in clock system

Immediate measures for SourceCodester Online Reviewer installations

No specific patch version is listed for the application in the related listings. Administrators should note if they are using version 1.0, limit the exposure of the admin panel to the web, and review logs for unusual calls to specific endpoints.

The SecNews technical team also recommends checking the difficulty_id and test_id, using prepared database queries, and strict input validation. In addition, the application and its server should be updated as soon as an official fix is ​​released by the maintainer.

Until there is a clear upgrade directive, organizations can implement rules at the firewall or reverse proxy to ensure that management paths are only available from predefined networks. At the same time, enabling multi-factor protection at the access level, where supported, reduces the risk of misuse of stolen credentials.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

SourceCodester Online Reviewer Parameter Check

See also: CVE-2026-19384 SourceCodester: Serious SQL injection in dating app

For organizations hosting SourceCodester Online Reviewer, the safest interim option is to isolate administrative functionality from untrusted networks and regularly review accounts. CVE documentation shows that the absence of checks on application parameters can turn a seemingly restricted functionality into an entry point for SQL injection.

Additionally, security officers can look for fingerprints of failed or unusual requests in the databank and pretest, as well as repeated values ​​in parameters reported in CVEs. Correlating these events with database connections helps determine if an exploitation attempt was made before access restrictions are applied.

The final recovery should be based on fixed code and not just network filters. After the upgrade, it is necessary to recheck the permissions of the base account, change credentials where in doubt, and maintain a backup before any change.

Protection measures for SourceCodester Online Reviewer
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS