Overview
A new SQL injection vulnerability has been disclosed in SourceCodester's Online Reviewer Management System v1.0, the same free PHP/MySQL exam-management template implicated in a recent cluster of injection flaws. Tracked as CVE-2026-102908, the issue lets a remote, unauthenticated attacker inject arbitrary SQL through the ID argument of questions-view.php, with exploitation described as easy and technical details already public.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-102908 |
| Severity | High (CVSS 3.1: 7.3) |
| CWE | CWE-89 (SQL Injection) |
| Vulnerable File | /reviewer_0/admins/assessments/examproper/questions-view.php |
| Parameter | ID |
| Authentication | None required |
| Exploit Maturity | Public exploit details available |
How It Works
The ID value supplied to questions-view.php — the page that renders a single exam question record within the examproper module — is concatenated directly into a backend SQL query rather than being passed through a parameterized statement (CWE-89). Because the script does not enforce a session check before processing the request, an attacker only needs network reachability to the endpoint, not valid admin credentials, to tamper with the query. A typical attack simply appends boolean- or time-based payloads to the id query-string value (e.g. questions-view.php?id= followed by injected SQL) to confirm the flaw and then extract data via UNION-based or blind techniques.
This is the second disclosure in a short span affecting the examproper/assessments area of this codebase — a related CVE covering a different file and parameter in the same module (btn_functions.php) was also reported around the same time. Deployments running this product should treat the injection pattern as systemic across the admin/assessments tree rather than isolated to a single endpoint, and audit sibling files in the same directory, not just the one named in this advisory.
Impact Assessment
Who Is At Risk
- Any organization or individual running Online Reviewer Management System v1.0 with the
admins/assessments/examproperpath reachable over the network - As with other SourceCodester-derived deployments, exposure is concentrated in small schools, training centers, and personal/portfolio installs that are rarely monitored or patched
Potential Impact
- Unauthorized read access to the application's full MySQL database, including exam questions, answer keys, student records, and stored admin credentials
- Data tampering or deletion via injected
UPDATE/DELETEstatements against the questions or assessments tables - Credential harvesting that enables further compromise if database or admin passwords are reused on other systems
Mitigation
- Rewrite the vulnerable query in
questions-view.phpto use parameterized queries or prepared statements, and audit the rest of theexamproperdirectory for the same pattern. No official vendor patch channel exists for this self-hosted template. - Deploy a Web Application Firewall (WAF) with SQL injection detection rules as an interim compensating control while code fixes are developed.
- Restrict network exposure of the admin/assessments module to trusted/internal networks only — it should not be internet-facing.
- Audit logs for prior exploitation — review database and web server logs for anomalous
idparameter values or unexpected query patterns against thequestionstable. - Given the recurring injection flaws surfacing across this product's assessments module, evaluate whether continued use is appropriate for any deployment handling real student or institutional data, and plan a migration path if not.