Vulnerability
CVE-2026-95924
Descriptive record received from OpenCTI and minimised for consultation in the Intel portal.
- Sharing
- PUBLIC-OSINT
- Confidence
- 100
- Source
- The CVE Program
- Updated
- 26/09/2026 08:14
Description
A vulnerability has been found in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=add. The manipulation of the argument difficulty_id leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Aliases and classifications
CWE-74CWE-89InjectionSQL Injection
Minimised technical details
No raw data- cvss score
- 7.3
- cvss severity
- HIGH
- cisa kev
- False
- cvss vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
Provenance
Public references
- VDB-408546 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/408546/cti - exploit
https://github.com/huliangjia/cve/issues/4 - VDB-408546 | SourceCodester Online Reviewer Management System btn_functions.php add sql injection
https://vuldb.com/vuln/408546 - product
https://www.sourcecodester.com/ - CVE-2026-95924 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-95924 - Submit #953303 | SourceCodester Online Reviewer Management System using PHP/MySQL /reviewer_0/admins/assessments/databank/btn_functions.php?action=add 1.0 SQL I
https://vuldb.com/submit/953303
EudorIA correlation
Intel catalogue
The vulnerability is also available in the EudorIA editorial catalogue.
Open EudorIA analysisPresence in OpenCTI describes an intelligence correlation and does not, by itself, constitute evidence of compromise, legal attribution or operational guidance applicable without context verification.