Overview
Another SQL injection flaw has surfaced in SourceCodester's Online Reviewer Management System 1.0, a free PHP/MySQL exam-management template widely reused in student capstone projects and small training centers. Tracked as CVE-2026-105182, the vulnerability lives in the activities module and lets a remote, unauthenticated attacker inject arbitrary SQL through the Title parameter of btn_functions.php when called with action=update.
This is the fourth distinct SQL injection CVE disclosed against this exact product within the past several weeks — following CVE-2026-93959 (Course parameter), CVE-2026-102908 (ID parameter in questions-view.php), and CVE-2026-102909 (access_code parameter, also in btn_functions.php) — underscoring that the application's admin-side input handling was never built with parameterized queries in mind.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-105182 |
| Severity | High (CVSS 3.1: 7.3) |
| CWE | CWE-89 — Improper Neutralization of Special Elements used in an SQL Command |
| Affected File | /reviewer_0/admins/assessments/activities/btn_functions.php |
| Vulnerable Parameter | Title (via action=update) |
| Attack Vector | Network |
| Authentication | None Required |
| Privileges Required | None |
| User Interaction | None |
| Exploit Status | Public exploit code released |
| Affected Versions | 1.0 |
| Fixed Versions | None available from vendor at time of publication |
How It Works
The btn_functions.php endpoint in the activities module accepts an action query parameter that routes to several admin functions, including update. When action=update is invoked, the script takes the attacker-supplied Title value and concatenates it directly into a SQL statement without escaping, sanitizing, or parameterizing the input. Because the endpoint performs no session or authentication check before processing the request, an attacker needs nothing more than network access to the application to submit a crafted Title value and manipulate the underlying query — enabling data extraction, modification, or deletion depending on the database account's privileges.
Public proof-of-concept exploit code for this vulnerability is already available, which typically accelerates automated scanning and exploitation attempts once a CVE is published.
Impact Assessment
Who Is At Risk
Any deployment of SourceCodester Online Reviewer Management System 1.0 reachable from an untrusted network is vulnerable, including installations used for:
- Student assessment and exam-proctoring portals at schools or training centers
- Capstone or portfolio demo projects left running on public hosting
- Internal review/quiz tools adapted from the original template without a security pass
Potential Attack Chains
- Discovery — Attacker identifies a reachable instance via fingerprinting the SourceCodester admin path structure
- Injection — Attacker sends a crafted
Titlevalue tobtn_functions.php?action=update - Extraction or Tampering — Depending on the injected payload, the attacker reads out database contents (user credentials, exam data) or alters/deletes records
- Escalation — If database credentials are reused or overly privileged, the attacker may pivot to broader system access
Mitigation
Immediate Actions
- Take internet-facing instances offline or restrict access to trusted networks until a fix is applied, as no vendor patch is currently available
- Audit the
activities/btn_functions.phpendpoint and rewrite theupdateaction to use parameterized queries or prepared statements for theTitlefield - Apply the same fix across the other known-vulnerable parameters in this product (
access_code,Course,ID) if not already remediated from prior CVEs
Detection Opportunities
- Monitor web server and database logs for anomalous SQL syntax (quotes,
UNION, comment sequences) in requests tobtn_functions.php - Flag unauthenticated requests reaching admin-path endpoints — a properly configured deployment should never allow this
Defence-in-Depth
- Deploy a web application firewall (WAF) with SQL injection rule sets in front of any instance that cannot be immediately patched
- Run the application's database account with least-privilege access, separate from any account with broader system rights
- Treat any publicly reused open-source PHP template as unaudited code; a security review before production deployment would have caught this class of bug across all four CVEs
Discovery & Disclosure
CVE-2026-105182 was reserved on October 4, 2026, and published on October 5, 2026, with VulDB as the CVE record assigner. As of publication, there is no evidence the flaw is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, but public exploit code is already circulating, which warrants urgent remediation or network isolation given the zero-authentication attack path.