VYPR
advisoryPublished Oct 5, 2026· 1 source

SourceCodester: Six Vulnerabilities Including SQLi Disclosed Together

Key findings • Six vulnerabilities disclosed on October 5, 2026, for SourceCodester products. • Four SQL injection flaws identified across Online Reviewer Management System and Drug Recommend…

Key findings

On October 5, 2026, a batch of six vulnerabilities was disclosed for various SourceCodester products, with a tight disclosure window of just two hours. The vulnerabilities, ranging in severity from Low to High, primarily impact the Drug Recommendation System 1.0 and the Online Reviewer Management System 1.0. The most critical of these flaws include SQL injection vulnerabilities, posing a significant risk to data integrity and system security.

The disclosed vulnerabilities can be categorized by their impact and affected components:

SQL Injection Vulnerabilities

Four of the six vulnerabilities are SQL injection flaws, allowing attackers to manipulate database queries.

  • **CVE-2026-105182** affects the Online Reviewer Management System 1.0, specifically in the file /reviewer_0/admins/assessments/activities/btn_functions.php. Manipulation of the 'Title' argument leads to SQL injection.
  • **CVE-2026-105178** impacts the Drug Recommendation System 1.0, within the /Admin/add_symptom.php file. A manipulation of the 'txtname' argument in the mysqli_real_escape_string function results in SQL injection.
  • **CVE-2026-105177** also targets the Drug Recommendation System 1.0, in the /Admin/add_drug.php file. Manipulating arguments such as 'txtname', 'cmdtype', 'txtusage', 'txtsideeffect', and 'cmdcontraindication' leads to SQL injection.
  • **CVE-2026-105175**, a High severity vulnerability, affects the Drug Recommendation System 1.0's Student Registration component (/Auth/add_student.php). Manipulation of the 'cmdschool' argument results in SQL injection. This vulnerability has been publicly disclosed and may be actively exploited.

Data Encryption Weakness

One vulnerability relates to data handling and encryption:

  • **CVE-2026-105179** affects the Drug Recommendation System 1.0's password handler in /Admin/add_user.php. A manipulation of the 'Password' argument leads to the missing encryption of sensitive data, a Low severity issue.

SQL Injection in File Editing

Another SQL injection vulnerability was found in file editing functionality:

  • **CVE-2026-105176** impacts the Drug Recommendation System 1.0, specifically within the /Admin/edit_class.php file. Manipulation of the 'ID' argument causes SQL injection. This vulnerability has also been publicly disclosed and may be exploited.

The simultaneous disclosure of these vulnerabilities highlights a potential pattern of weaknesses in SourceCodester's web application systems. The presence of multiple SQL injection flaws, some of which have been publicly disclosed, indicates a need for immediate attention from users of the affected SourceCodester products. While specific patch information or version updates were not detailed in the disclosures, users are strongly advised to consult SourceCodester's official advisories for mitigation strategies and available fixes. The remote nature of these attacks means that systems accessible from the internet are particularly at risk.

This batch of vulnerabilities underscores the importance of regular security audits and timely patching for all web applications, especially those handling user data and administrative functions. The public disclosure of some of these flaws suggests that threat actors may already be attempting to exploit them.

Key Findings

Synthesized by Vypr AI