SECURITYHIGHCVE-2026-102909

CVE-2026-102909: SQL Injection in SourceCodester Online Reviewer Management System via access_code

CVE-2026-102909: SourceCodester Online Reviewer Management System 1.0 allows remote SQL injection via the access_code parameter in btn_functions.php.

Dylan H.

Security Team

September 30, 2026
5 min read
CVE-2026-102909: SQL Injection in SourceCodester Online Reviewer Management System via access_code

Affected Products

  • SourceCodester Online Reviewer Management System 1.0

Overview

A SQL injection vulnerability tracked as CVE-2026-102909 has been disclosed in SourceCodester's Online Reviewer Management System 1.0, a free PHP/MySQL exam-management template commonly reused in small schools, training centers, and student capstone projects. The flaw lives in the exam-proctoring admin module and allows a remote, unauthenticated attacker to inject arbitrary SQL through the access_code parameter of btn_functions.php.

The issue was published on September 30, 2026 and is tracked under CWE-89 — Improper Neutralization of Special Elements used in an SQL Command. NVD lists a CVSS v3.1 score of 7.3 (High); some third-party aggregators have scored it slightly lower, but the consensus across trackers is that exploitation is remote, requires no authentication, and is rated as easy to carry out.


Technical Details

AttributeValue
CVE IDCVE-2026-102909
CVSS Score7.3 (High)
CWE ClassificationCWE-89 — SQL Injection
Affected SoftwareSourceCodester Online Reviewer Management System 1.0
Vulnerable File/reviewer_0/admins/assessments/examproper/btn_functions.php
Vulnerable Parameteraccess_code
Attack VectorNetwork (Remote)
Authentication RequiredNone
CISA KEV StatusNot listed
Patch AvailableNone confirmed

How It Works

The access_code value submitted to btn_functions.php in the examproper (exam proctoring) module is concatenated directly into a backend SQL statement instead of being passed through a parameterized query or bound statement. Because the endpoint sits behind no authentication check, an attacker only needs network-level access to reach it — no valid session, admin credentials, or prior foothold is required.

A typical exploitation attempt would append injectable syntax to the access_code value, for example:

POST /reviewer_0/admins/assessments/examproper/btn_functions.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded

access_code=1' OR '1'='1' UNION SELECT NULL,username,password,NULL FROM admins--

A successful injection can be used to:

  • Enumerate the backend schema — identify tables, columns, and stored data via information_schema queries
  • Bypass the exam access-code check entirely — forging a valid proctoring session without a legitimate code
  • Exfiltrate stored data — including administrator credentials, student records, and exam content held in the MySQL database
  • Attempt data tampering — via injected UPDATE/DELETE statements where the database account has write privileges

A Recurring Pattern in This Codebase

This is not an isolated defect. SourceCodester's Online Reviewer Management System has accumulated a cluster of near-identical SQL injection findings across different btn_functions.php instances scattered throughout the admins/assessments module — each tied to a different form parameter in a different submodule. Deployments running this codebase should treat the injection pattern as systemic to the admin/assessments area rather than isolated to the examproper endpoint covered here, and should audit all btn_functions.php files under admins/assessments/ rather than patching this single file in isolation.


Impact Assessment

Impact AreaDescription
Authentication BypassCrafted access_code input may bypass exam proctoring checks entirely
Data ExposureAdmin credentials, student records, and exam content stored in MySQL are exfiltrable
Data IntegrityInjected UPDATE/DELETE statements could alter or destroy exam and grading data
Exposure ProfileTypically deployed on low-visibility, unmonitored hosts (schools, training centers, portfolio projects)
Detection DifficultyNo vendor patch or official advisory to reference; defenders must self-diagnose

Who Is At Risk

  • Any organization or individual running Online Reviewer Management System v1.0 with the admin/assessments module reachable over the network
  • Educational institutions and training providers are the primary deployment base for this template, meaning student PII and exam integrity are both directly exposed
  • Instances are easily located via search-engine dorking against the distinctive /reviewer_0/ path structure, making mass scanning for vulnerable hosts straightforward

Mitigation / Recommendations

No official patch is currently available from SourceCodester for this product. Until a fix exists, treat this as unmaintained template software and apply compensating controls directly.

For Administrators

  • Take the examproper endpoint off the public internet. Restrict /reviewer_0/admins/ to a trusted internal network, VPN, or IP allowlist — it has no business being reachable from the open web.
  • Rewrite the vulnerable query in btn_functions.php to use parameterized queries or prepared statements (e.g., PDO with bound parameters, or mysqli prepared statements) rather than string concatenation.
  • Audit every btn_functions.php file under admins/assessments/ for the same unsanitized-input pattern — this flaw is very unlikely to be unique to the examproper module.

For Security Teams

  • Deploy WAF rules targeting SQL injection payloads on the access_code parameter and related admin/assessments endpoints as an interim compensating control.
  • Review database and web server logs for anomalous queries referencing access_code, UNION SELECT, or information_schema against this application's database.
  • Rotate credentials for any database or admin accounts associated with the application if evidence of prior exploitation is found.

For Organizations Running This Software

  • Evaluate whether continued use of Online Reviewer Management System is appropriate for any deployment that handles real student records, exam content, or institutional data, given the recurring injection pattern across this codebase.
  • Consider migrating to a maintained exam/assessment platform with an active security response process.

Key Takeaways

  1. CVE-2026-102909 is a CVSS 7.3 (High) SQL injection in SourceCodester Online Reviewer Management System 1.0, affecting /reviewer_0/admins/assessments/examproper/btn_functions.php.
  2. The access_code parameter is concatenated unsanitized into a backend SQL query, allowing remote, unauthenticated injection (CWE-89).
  3. Exploitation can bypass exam access-code checks and exfiltrate admin credentials, student records, and exam content.
  4. This flaw is part of a broader, recurring pattern of SQL injection issues across btn_functions.php files in the same product's admin/assessments module.
  5. No official patch exists — administrators must restrict network access to the admin module and retrofit parameterized queries themselves.
  6. The product's typical use in schools and training centers raises the stakes: student PII and exam integrity are both directly exposed.

Sources