CVE-2026-2198 | code-projects Online Reviewer System 1.0 loaddata.php difficulty_id sql injection (CNNVD-202602-1399)
A vulnerability labeled as critical has been found in code-projects Online Reviewer System 1.0. The affected element is an unknown function of the file /system/system/admins/assessments/pretest/loaddata.php. Such manipulation of the argument difficulty_id leads to sql injection.
This vulnerability is referenced as CVE-2026-2198. It is possible to launch the attack remotely. Furthermore, an exploit is available.