Overview
A SQL injection vulnerability tracked as CVE-2026-102909 has been disclosed in SourceCodester's Online Reviewer Management System 1.0, a free PHP/MySQL exam-management template commonly reused in small schools, training centers, and student capstone projects. The flaw lives in the exam-proctoring admin module and allows a remote, unauthenticated attacker to inject arbitrary SQL through the access_code parameter of btn_functions.php.
The issue was published on September 30, 2026 and is tracked under CWE-89 — Improper Neutralization of Special Elements used in an SQL Command. NVD lists a CVSS v3.1 score of 7.3 (High); some third-party aggregators have scored it slightly lower, but the consensus across trackers is that exploitation is remote, requires no authentication, and is rated as easy to carry out.
Technical Details
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-102909 |
| CVSS Score | 7.3 (High) |
| CWE Classification | CWE-89 — SQL Injection |
| Affected Software | SourceCodester Online Reviewer Management System 1.0 |
| Vulnerable File | /reviewer_0/admins/assessments/examproper/btn_functions.php |
| Vulnerable Parameter | access_code |
| Attack Vector | Network (Remote) |
| Authentication Required | None |
| CISA KEV Status | Not listed |
| Patch Available | None confirmed |
How It Works
The access_code value submitted to btn_functions.php in the examproper (exam proctoring) module is concatenated directly into a backend SQL statement instead of being passed through a parameterized query or bound statement. Because the endpoint sits behind no authentication check, an attacker only needs network-level access to reach it — no valid session, admin credentials, or prior foothold is required.
A typical exploitation attempt would append injectable syntax to the access_code value, for example:
POST /reviewer_0/admins/assessments/examproper/btn_functions.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
access_code=1' OR '1'='1' UNION SELECT NULL,username,password,NULL FROM admins--
A successful injection can be used to:
- Enumerate the backend schema — identify tables, columns, and stored data via
information_schemaqueries - Bypass the exam access-code check entirely — forging a valid proctoring session without a legitimate code
- Exfiltrate stored data — including administrator credentials, student records, and exam content held in the MySQL database
- Attempt data tampering — via injected
UPDATE/DELETEstatements where the database account has write privileges
A Recurring Pattern in This Codebase
This is not an isolated defect. SourceCodester's Online Reviewer Management System has accumulated a cluster of near-identical SQL injection findings across different btn_functions.php instances scattered throughout the admins/assessments module — each tied to a different form parameter in a different submodule. Deployments running this codebase should treat the injection pattern as systemic to the admin/assessments area rather than isolated to the examproper endpoint covered here, and should audit all btn_functions.php files under admins/assessments/ rather than patching this single file in isolation.
Impact Assessment
| Impact Area | Description |
|---|---|
| Authentication Bypass | Crafted access_code input may bypass exam proctoring checks entirely |
| Data Exposure | Admin credentials, student records, and exam content stored in MySQL are exfiltrable |
| Data Integrity | Injected UPDATE/DELETE statements could alter or destroy exam and grading data |
| Exposure Profile | Typically deployed on low-visibility, unmonitored hosts (schools, training centers, portfolio projects) |
| Detection Difficulty | No vendor patch or official advisory to reference; defenders must self-diagnose |
Who Is At Risk
- Any organization or individual running Online Reviewer Management System v1.0 with the admin/assessments module reachable over the network
- Educational institutions and training providers are the primary deployment base for this template, meaning student PII and exam integrity are both directly exposed
- Instances are easily located via search-engine dorking against the distinctive
/reviewer_0/path structure, making mass scanning for vulnerable hosts straightforward
Mitigation / Recommendations
No official patch is currently available from SourceCodester for this product. Until a fix exists, treat this as unmaintained template software and apply compensating controls directly.
For Administrators
- Take the
examproperendpoint off the public internet. Restrict/reviewer_0/admins/to a trusted internal network, VPN, or IP allowlist — it has no business being reachable from the open web. - Rewrite the vulnerable query in
btn_functions.phpto use parameterized queries or prepared statements (e.g., PDO with bound parameters, ormysqliprepared statements) rather than string concatenation. - Audit every
btn_functions.phpfile underadmins/assessments/for the same unsanitized-input pattern — this flaw is very unlikely to be unique to theexampropermodule.
For Security Teams
- Deploy WAF rules targeting SQL injection payloads on the
access_codeparameter and related admin/assessments endpoints as an interim compensating control. - Review database and web server logs for anomalous queries referencing
access_code,UNION SELECT, orinformation_schemaagainst this application's database. - Rotate credentials for any database or admin accounts associated with the application if evidence of prior exploitation is found.
For Organizations Running This Software
- Evaluate whether continued use of Online Reviewer Management System is appropriate for any deployment that handles real student records, exam content, or institutional data, given the recurring injection pattern across this codebase.
- Consider migrating to a maintained exam/assessment platform with an active security response process.
Key Takeaways
- CVE-2026-102909 is a CVSS 7.3 (High) SQL injection in SourceCodester Online Reviewer Management System 1.0, affecting
/reviewer_0/admins/assessments/examproper/btn_functions.php. - The
access_codeparameter is concatenated unsanitized into a backend SQL query, allowing remote, unauthenticated injection (CWE-89). - Exploitation can bypass exam access-code checks and exfiltrate admin credentials, student records, and exam content.
- This flaw is part of a broader, recurring pattern of SQL injection issues across
btn_functions.phpfiles in the same product's admin/assessments module. - No official patch exists — administrators must restrict network access to the admin module and retrofit parameterized queries themselves.
- The product's typical use in schools and training centers raises the stakes: student PII and exam integrity are both directly exposed.