<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-102908 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-102908/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 30 Sep 2026 04:31:33 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-102908/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>SQL Injection in SourceCodester Online Reviewer Management System</title><link>https://feed.craftedsignal.io/briefs/2026-09-sourcecodester-sql-injection/</link><pubDate>Wed, 30 Sep 2026 04:31:33 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-sourcecodester-sql-injection/</guid><description>SourceCodester Online Reviewer Management System 1.0 contains a SQL injection vulnerability in the questions-view.php script, allowing remote attackers to execute unauthorized database queries.</description><content:encoded><![CDATA[<p>A SQL injection vulnerability has been identified in SourceCodester Online Reviewer Management System version 1.0. The vulnerability resides within the file /reviewer_0/admins/assessments/examproper/questions-view.php. An attacker can perform remote exploitation by manipulating the ID parameter passed to this script. Successful exploitation allows for the execution of arbitrary SQL commands against the backend database, potentially leading to unauthorized data exfiltration, modification, or administrative access to the underlying management system. Given that the exploit has been publicly disclosed, organizations utilizing this software are at an elevated risk of automated or targeted exploitation attempts.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-102908 permits an unauthenticated remote attacker to compromise the integrity and confidentiality of the application database. Potential impacts include the dumping of sensitive reviewer or exam information, modification of administrative credentials, or full takeover of the application instance.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Monitor web server access logs for anomalous GET or POST requests directed at /reviewer_0/admins/assessments/examproper/questions-view.php containing SQL syntax characters (e.g., apostrophes, double-dashes, keywords like UNION or SELECT).</li>
<li>Apply input validation and parameterized queries to the ID parameter in the affected PHP script.</li>
<li>Implement a Web Application Firewall (WAF) to block requests containing common SQL injection patterns targeting the identified endpoint.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>sql-injection</category><category>web-application</category><category>cve-2026-102908</category><category>web-application-vulnerability</category><category>vulnerability-management</category></item></channel></rss>