SECURITYHIGHCVE-2026-102908

CVE-2026-102908: Unauthenticated SQL Injection in SourceCodester Online Reviewer Management System

SourceCodester Online Reviewer Management System v1.0's questions-view.php lets remote, unauthenticated attackers inject SQL via the ID parameter.

Dylan H.

Security Team

September 30, 2026
3 min read
CVE-2026-102908: Unauthenticated SQL Injection in SourceCodester Online Reviewer Management System

Affected Products

  • SourceCodester Online Reviewer Management System v1.0

Overview

A new SQL injection vulnerability has been disclosed in SourceCodester's Online Reviewer Management System v1.0, the same free PHP/MySQL exam-management template implicated in a recent cluster of injection flaws. Tracked as CVE-2026-102908, the issue lets a remote, unauthenticated attacker inject arbitrary SQL through the ID argument of questions-view.php, with exploitation described as easy and technical details already public.


Technical Details

FieldValue
CVE IDCVE-2026-102908
SeverityHigh (CVSS 3.1: 7.3)
CWECWE-89 (SQL Injection)
Vulnerable File/reviewer_0/admins/assessments/examproper/questions-view.php
ParameterID
AuthenticationNone required
Exploit MaturityPublic exploit details available

How It Works

The ID value supplied to questions-view.php — the page that renders a single exam question record within the examproper module — is concatenated directly into a backend SQL query rather than being passed through a parameterized statement (CWE-89). Because the script does not enforce a session check before processing the request, an attacker only needs network reachability to the endpoint, not valid admin credentials, to tamper with the query. A typical attack simply appends boolean- or time-based payloads to the id query-string value (e.g. questions-view.php?id= followed by injected SQL) to confirm the flaw and then extract data via UNION-based or blind techniques.

This is the second disclosure in a short span affecting the examproper/assessments area of this codebase — a related CVE covering a different file and parameter in the same module (btn_functions.php) was also reported around the same time. Deployments running this product should treat the injection pattern as systemic across the admin/assessments tree rather than isolated to a single endpoint, and audit sibling files in the same directory, not just the one named in this advisory.


Impact Assessment

Who Is At Risk

  • Any organization or individual running Online Reviewer Management System v1.0 with the admins/assessments/examproper path reachable over the network
  • As with other SourceCodester-derived deployments, exposure is concentrated in small schools, training centers, and personal/portfolio installs that are rarely monitored or patched

Potential Impact

  • Unauthorized read access to the application's full MySQL database, including exam questions, answer keys, student records, and stored admin credentials
  • Data tampering or deletion via injected UPDATE/DELETE statements against the questions or assessments tables
  • Credential harvesting that enables further compromise if database or admin passwords are reused on other systems

Mitigation

  • Rewrite the vulnerable query in questions-view.php to use parameterized queries or prepared statements, and audit the rest of the examproper directory for the same pattern. No official vendor patch channel exists for this self-hosted template.
  • Deploy a Web Application Firewall (WAF) with SQL injection detection rules as an interim compensating control while code fixes are developed.
  • Restrict network exposure of the admin/assessments module to trusted/internal networks only — it should not be internet-facing.
  • Audit logs for prior exploitation — review database and web server logs for anomalous id parameter values or unexpected query patterns against the questions table.
  • Given the recurring injection flaws surfacing across this product's assessments module, evaluate whether continued use is appropriate for any deployment handling real student or institutional data, and plan a migration path if not.

References