Vulnerabilidad · Publicado 05/10/2026
Se identificó una vulnerabilidad de inyección SQL en SourceCodester Online Reviewer Management System versión 1.0, específicamente en el parámetro Subject del archivo btn_functions.php?action=update. La vulnerabilidad permite a atacantes remotos manipular consultas SQL y comprometer la integridad de bases de datos. El exploit está públicamente disponible y afecta principalmente a instituciones educativas y plataformas de evaluación académica en LATAM.
A vulnerability was found in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/Subject/btn_functions.php?action=update. Performing a manipulation of the argument Subject results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.
Score: 7.3/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CWE-74, CWE-89
Publicado en NIST NVD.