SourceCodester: Six Vulnerabilities Including SQLi Disclosed Together
Six vulnerabilities, including critical SQL injection flaws, were disclosed for SourceCodester products on October 5, 2026, impacting data integrity and security.

Key findings
- Six vulnerabilities disclosed on October 5, 2026, for SourceCodester products.
- Four SQL injection flaws identified across Online Reviewer Management System and Drug Recommendation System.
- Two High severity vulnerabilities (CVE-2026-105182, CVE-2026-105175) pose significant risks.
- CVE-2026-105175 and CVE-2026-105176 have been publicly disclosed, increasing exploitability.
- One vulnerability (CVE-2026-105179) leads to missing encryption of sensitive data.
- Affected products include Drug Recommendation System 1.0 and Online Reviewer Management System 1.0.
On October 5, 2026, a batch of six vulnerabilities was disclosed for various SourceCodester products, with a tight disclosure window of just two hours. The vulnerabilities, ranging in severity from Low to High, primarily impact the Drug Recommendation System 1.0 and the Online Reviewer Management System 1.0. The most critical of these flaws include SQL injection vulnerabilities, posing a significant risk to data integrity and system security.
The disclosed vulnerabilities can be categorized by their impact and affected components:
SQL Injection Vulnerabilities
Four of the six vulnerabilities are SQL injection flaws, allowing attackers to manipulate database queries.
- **CVE-2026-105182** affects the Online Reviewer Management System 1.0, specifically in the file
/reviewer_0/admins/assessments/activities/btn_functions.php. Manipulation of the 'Title' argument leads to SQL injection. - **CVE-2026-105178** impacts the Drug Recommendation System 1.0, within the
/Admin/add_symptom.phpfile. A manipulation of the 'txtname' argument in themysqli_real_escape_stringfunction results in SQL injection. - **CVE-2026-105177** also targets the Drug Recommendation System 1.0, in the
/Admin/add_drug.phpfile. Manipulating arguments such as 'txtname', 'cmdtype', 'txtusage', 'txtsideeffect', and 'cmdcontraindication' leads to SQL injection. - **CVE-2026-105175**, a High severity vulnerability, affects the Drug Recommendation System 1.0's Student Registration component (
/Auth/add_student.php). Manipulation of the 'cmdschool' argument results in SQL injection. This vulnerability has been publicly disclosed and may be actively exploited.
Data Encryption Weakness
One vulnerability relates to data handling and encryption:
- **CVE-2026-105179** affects the Drug Recommendation System 1.0's password handler in
/Admin/add_user.php. A manipulation of the 'Password' argument leads to the missing encryption of sensitive data, a Low severity issue.
SQL Injection in File Editing
Another SQL injection vulnerability was found in file editing functionality:
- **CVE-2026-105176** impacts the Drug Recommendation System 1.0, specifically within the
/Admin/edit_class.phpfile. Manipulation of the 'ID' argument causes SQL injection. This vulnerability has also been publicly disclosed and may be exploited.
The simultaneous disclosure of these vulnerabilities highlights a potential pattern of weaknesses in SourceCodester's web application systems. The presence of multiple SQL injection flaws, some of which have been publicly disclosed, indicates a need for immediate attention from users of the affected SourceCodester products. While specific patch information or version updates were not detailed in the disclosures, users are strongly advised to consult SourceCodester's official advisories for mitigation strategies and available fixes. The remote nature of these attacks means that systems accessible from the internet are particularly at risk.
This batch of vulnerabilities underscores the importance of regular security audits and timely patching for all web applications, especially those handling user data and administrative functions. The public disclosure of some of these flaws suggests that threat actors may already be attempting to exploit them.
Key Findings
- Six vulnerabilities disclosed on October 5, 2026, for SourceCodester products.
- Four SQL injection flaws identified across Online Reviewer Management System and Drug Recommendation System.
- Two High severity vulnerabilities (CVE-2026-105182, CVE-2026-105175) pose significant risks.
- CVE-2026-105175 and CVE-2026-105176 have been publicly disclosed, increasing exploitability.
- One vulnerability (CVE-2026-105179) leads to missing encryption of sensitive data.
- Affected products include Drug Recommendation System 1.0 and Online Reviewer Management System 1.0.
- cve_ids: CVE-2026-105182, CVE-2026-105179, CVE-2026-105178, CVE-2026-105177, CVE-2026-105176, CVE-2026-105175
- image_prompt: A stylized database icon with visible cracks, from which SQL code snippets are leaking out, set against a dark, binary-code background.
- title: SourceCodester: Six Vulnerabilities Including SQLi Disclosed Together
- lede: Six vulnerabilities, including critical SQL injection flaws, were disclosed for SourceCodester products on October 5, 2026, impacting data integrity and security.