A security vulnerability has been detected in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/course/btn_functions.php. Such manipulation of the argument courseID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
SourceCodester Online Reviewer Management System btn_functions.php sql injection
Problem type
Affected products
SourceCodester
1.0 - AFFECTED
References
https://vuldb.com/vuln/407931
https://vuldb.com/vuln/407931/cti
https://vuldb.com/cve/CVE-2026-93972
https://vuldb.com/submit/944506
https://vuldb.com/submit/944534
https://github.com/orzl1/cve/issues/1
https://www.sourcecodester.com/
GitHub Security Advisories
GHSA-wgcc-xrgh-mmvj
A security vulnerability has been detected in SourceCodester Online Reviewer Management System 1...
https://github.com/advisories/GHSA-wgcc-xrgh-mmvjA security vulnerability has been detected in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/course/btn_functions.php. Such manipulation of the argument courseID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
https://nvd.nist.gov/vuln/detail/CVE-2026-93972
https://github.com/orzl1/cve/issues/1
https://vuldb.com/cve/CVE-2026-93972
https://vuldb.com/submit/944506
https://vuldb.com/submit/944534
https://vuldb.com/vuln/407931
https://vuldb.com/vuln/407931/cti
https://www.sourcecodester.com
https://github.com/advisories/GHSA-wgcc-xrgh-mmvj
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-93972Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-93972",
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"dateUpdated": "2026-09-20T07:45:07.351Z",
"dateReserved": "2026-09-19T10:17:55.270Z",
"datePublished": "2026-09-20T07:45:07.351Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB",
"dateUpdated": "2026-09-20T07:45:07.351Z"
},
"title": "SourceCodester Online Reviewer Management System btn_functions.php sql injection",
"descriptions": [
{
"lang": "en",
"value": "A security vulnerability has been detected in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/course/btn_functions.php. Such manipulation of the argument courseID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used."
}
],
"affected": [
{
"vendor": "SourceCodester",
"product": "Online Reviewer Management System",
"cpes": [
"cpe:2.3:a:sourcecodester:online_reviewer_management_system:*:*:*:*:*:*:*:*"
],
"versions": [
{
"version": "1.0",
"status": "affected"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "SQL Injection",
"cweId": "CWE-89",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"lang": "en",
"description": "Injection",
"cweId": "CWE-74",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://vuldb.com/vuln/407931",
"name": "VDB-407931 | SourceCodester Online Reviewer Management System btn_functions.php sql injection",
"tags": [
"vdb-entry",
"technical-description"
]
},
{
"url": "https://vuldb.com/vuln/407931/cti",
"name": "VDB-407931 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
]
},
{
"url": "https://vuldb.com/cve/CVE-2026-93972",
"name": "CVE-2026-93972 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://vuldb.com/submit/944506",
"name": "Submit #944506 | SourceCodester Online Reviewer Management System using PHP with Source Code V1.0 /reviewer_0/admins/assessments/course/btn_functions.php?action 1.0 SQL Injection",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://vuldb.com/submit/944534",
"name": "Submit #944534 | SourceCodester Online Reviewer Management System /reviewer_0/admins/assessments/course/btn_functions.php?action=remove&courseID=7 1.0 SQL Injection (Duplicate)",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://github.com/orzl1/cve/issues/1",
"tags": [
"exploit",
"issue-tracking"
]
},
{
"url": "https://www.sourcecodester.com/",
"tags": [
"product"
]
}
],
"metrics": [
{},
{
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"baseScore": 7.3,
"baseSeverity": "HIGH"
}
},
{
"cvssV3_0": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"baseScore": 7.3,
"baseSeverity": "HIGH"
}
},
{
"cvssV2_0": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"baseScore": 7.5
}
}
],
"timeline": [
{
"time": "2026-09-19T00:00:00.000Z",
"lang": "en",
"value": "Advisory disclosed"
},
{
"time": "2026-09-19T02:00:00.000Z",
"lang": "en",
"value": "VulDB entry created"
},
{
"time": "2026-09-19T12:22:59.000Z",
"lang": "en",
"value": "VulDB entry last update"
}
],
"credits": [
{
"lang": "en",
"value": "pnpe (VulDB User)",
"type": "reporter"
}
],
"tags": [
"x_freeware"
]
}
}
}