{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/online-reviewer-management-system-1.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:sourcecodester:online_reviewer_management_system:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-93959"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Online Reviewer Management System (1.0)"],"_cs_severities":["high"],"_cs_tags":["sql-injection","web-vulnerability"],"_cs_type":"advisory","_cs_vendors":["SourceCodester"],"content_html":"\u003cp\u003eSourceCodester Online Reviewer Management System version 1.0 contains a critical SQL injection vulnerability identified as CVE-2026-93959. The flaw exists within the 'btn_functions.php' script located in the '/reviewer_0/admins/assessments/course/' directory. An unauthenticated remote attacker can exploit this by sending a crafted HTTP request containing malicious SQL syntax within the 'Course' argument. Successful exploitation allows the attacker to manipulate the underlying database queries, which may lead to unauthorized data exfiltration, modification of database contents, or in some configurations, administrative access. Given that public exploit code is already disclosed, defenders should prioritize patching or restricting access to the affected web directory.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify instances of the SourceCodester Online Reviewer Management System.\u003c/li\u003e\n\u003cli\u003eAttacker sends a crafted HTTP GET or POST request to '/reviewer_0/admins/assessments/course/btn_functions.php'.\u003c/li\u003e\n\u003cli\u003eAttacker injects malicious SQL payload into the 'Course' parameter.\u003c/li\u003e\n\u003cli\u003eThe web server processes the request and passes the unsanitized input to the database backend.\u003c/li\u003e\n\u003cli\u003eThe database executes the injected query, returning unauthorized data or performing requested modifications.\u003c/li\u003e\n\u003cli\u003eAttacker exfiltrates sensitive database content or establishes persistent access via database functions.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows unauthenticated remote attackers to compromise the integrity and confidentiality of the database. This can lead to the loss of user credentials, system configuration details, or other sensitive information hosted within the application. Organizations utilizing this software in production environments face a high risk of total database compromise if the application is internet-facing.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediate mitigation: Restrict access to the '/reviewer_0/admins/assessments/course/' directory via web server access controls (e.g., allowlisting IP addresses).\u003c/li\u003e\n\u003cli\u003eDetection engineering: Deploy the web server detection rule below to monitor for SQL injection attempts against the identified endpoint.\u003c/li\u003e\n\u003cli\u003ePatch management: Monitor the SourceCodester vendor site for an official security update addressing CVE-2026-93959 and apply it to all production instances of the Online Reviewer Management System.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-20T04:17:23Z","date_published":"2026-09-20T04:17:23Z","id":"https://feed.craftedsignal.io/briefs/2026-09-sql-injection-online-reviewer/","summary":"SourceCodester Online Reviewer Management System 1.0 is vulnerable to remote SQL injection via the 'Course' parameter, allowing unauthenticated attackers to manipulate database queries.","title":"SQL Injection in SourceCodester Online Reviewer Management System","url":"https://feed.craftedsignal.io/briefs/2026-09-sql-injection-online-reviewer/"}],"language":"en","title":"CraftedSignal Threat Feed - Online Reviewer Management System (1.0)","version":"https://jsonfeed.org/version/1.1"}