SQL Injection Vulnerability in Sourcecodester Online Thesis Archiving System
CVE-2026-36948
7.3HIGH
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 13 April 2026
What is CVE-2026-36948?
The Sourcecodester Online Thesis Archiving System version 1.0 is vulnerable to a SQL injection attack via the view_archive.php endpoint. This vulnerability allows attackers to manipulate SQL queries, potentially leading to unauthorized access to sensitive data stored in the database. Proper input validation and prepared statements should be implemented to mitigate this risk.
