CVE-2026-2198

HIGH

Fabian Online Reviewer System - Injection

Title source: rule

Description

A vulnerability was identified in code-projects Online Reviewer System 1.0. The affected element is an unknown function of the file /system/system/admins/assessments/pretest/loaddata.php. Such manipulation of the argument difficulty_id leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

Scores

CVSS v3 7.3
EPSS 0.0003
EPSS Percentile 7.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Classification

CWE
CWE-74 CWE-89
Status published

Affected Products (1)

fabian/online_reviewer_system

Timeline

Published Feb 09, 2026
Tracked Since Feb 18, 2026