SQL Injection Vulnerability in Sourcecodester Online Thesis Archiving System
CVE-2026-36948

7.3HIGH

What is CVE-2026-36948?

The Sourcecodester Online Thesis Archiving System version 1.0 is vulnerable to a SQL injection attack via the view_archive.php endpoint. This vulnerability allows attackers to manipulate SQL queries, potentially leading to unauthorized access to sensitive data stored in the database. Proper input validation and prepared statements should be implemented to mitigate this risk.

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.