CVE-2026-95924
Scheda descrittiva ricevuta da OpenCTI e minimizzata per la consultazione nel portale Intel.
- Condivisione
- PUBLIC-OSINT
- Confidenza
- 100
- Fonte
- The CVE Program
- Aggiornata
- 26/09/2026 08:14
Descrizione
A vulnerability has been found in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=add. The manipulation of the argument difficulty_id leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Alias e classificazioni
Dettagli tecnici minimizzati
Nessun dato grezzo- cvss score
- 7.3
- cvss severity
- HIGH
- cisa kev
- False
- cvss vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
Riferimenti pubblici
- VDB-408546 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/408546/cti - exploit
https://github.com/huliangjia/cve/issues/4 - VDB-408546 | SourceCodester Online Reviewer Management System btn_functions.php add sql injection
https://vuldb.com/vuln/408546 - product
https://www.sourcecodester.com/ - CVE-2026-95924 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-95924 - Submit #953303 | SourceCodester Online Reviewer Management System using PHP/MySQL /reviewer_0/admins/assessments/databank/btn_functions.php?action=add 1.0 SQL I
https://vuldb.com/submit/953303
Catalogo Intel
La vulnerabilità è presente anche nel catalogo editoriale EudorIA.
Apri analisi EudorIALa presenza in OpenCTI descrive una correlazione di intelligence e non costituisce, da sola, prova di compromissione, attribuzione legale o indicazione operativa applicabile senza verifica del contesto.