CVE-2026-2197 | code-projects Online Reviewer System 1.0 exam-delete.php test_id sql injection
A vulnerability identified as critical has been detected in code-projects Online Reviewer System 1.0. Impacted is an unknown function of the file /system/system/admins/assessments/pretest/exam-delete.php. This manipulation of the argument test_id causes sql injection.
The identification of this vulnerability is CVE-2026-2197. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.