Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Very High
CVE-2021-41646
Disclosure Date: October 29, 2021 (last updated November 28, 2024)
Remote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously crafted PHP file that bypasses the image upload filters..
2
Attacker Value
Unknown
CVE-2023-2596
Disclosure Date: May 09, 2023 (last updated October 08, 2023)
A vulnerability was found in SourceCodester Online Reviewer System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /reviewer/system/system/admins/manage/users/user-update.php of the component GET Parameter Handler. The manipulation of the argument user_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-228398 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-25432
Disclosure Date: February 28, 2023 (last updated October 08, 2023)
An issue was discovered in Online Reviewer Management System v1.0. There is a SQL injection that can directly issue instructions to the background database system via reviewer_0/admins/assessments/course/course-update.php.
0
Attacker Value
Unknown
CVE-2023-25431
Disclosure Date: February 28, 2023 (last updated October 08, 2023)
An issue was discovered in Online Reviewer Management System v1.0. There is a XSS vulnerability via reviewer_0/admins/assessments/course/course-update.php.
0
Attacker Value
Unknown
CVE-2023-1038
Disclosure Date: February 26, 2023 (last updated October 08, 2023)
A vulnerability classified as critical has been found in SourceCodester Online Reviewer Management System 1.0. Affected is an unknown function of the file /reviewer_0/admins/assessments/pretest/questions-view.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-221796.
0
Attacker Value
Unknown
CVE-2021-44090
Disclosure Date: January 20, 2022 (last updated October 07, 2023)
An SQL Injection vulnerability exists in Sourcecodester Online Reviewer System 1.0 via the password parameter.
0
Attacker Value
Unknown
CVE-2021-27130
Disclosure Date: April 14, 2021 (last updated February 22, 2025)
Online Reviewer System 1.0 contains a SQL injection vulnerability through authentication bypass, which may lead to a reverse shell upload.
0