Description
A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /Auth/add_student.php of the component Student Registration. The manipulation of the argument cmdschool results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
Published: 2026-10-05
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Remote SQL Injection
Action: Patch ASAP
AI Analysis

Impact

Affected is SourceCodester Drug Recommendation System 1.0, specifically the add_student.php processing. The argument cmdschool is improperly sanitized, allowing attackers to inject arbitrary SQL commands. This can lead to unauthorized data disclosure, modification, or deletion within the system's database. The flaw represents an SQL injection vulnerability (CWE-89) and potentially an input manipulation weakness (CWE-74).

Affected Systems

The product is SourceCodester Drug Recommendation System version 1.0, with the vulnerable file Auth/add_student.php in the Student Registration component. No further sub-version details are provided. Administrators should confirm that their deployed instance uses this version and that the cmdschool parameter remains exposed.

Risk and Exploitability

The CVSS score of 6.9 signals a moderate to high risk level, and the exploit is publicly available, meaning attackers can easily craft malicious requests. EPSS data is not available, but the vulnerability being listed on vulnerability databases indicates it may be actively exploited. This flaw is not yet in CISA KEV, yet it is remotely exploitable as the attacker can submit input from any network location. Attackers could retrieve or corrupt patient or user data, causing integrity or availability damage.

Generated by OpenCVE AI on October 5, 2026 at 02:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply vendor patch or upgrade to a patched version of SourceCodester Drug Recommendation System if available
  • Restrict the cmdschool parameter to a whitelist of expected values or remove it from external input
  • Implement input validation and use parameterized queries to prevent SQL injection
  • Apply a Web Application Firewall to detect and block injection attempts

Generated by OpenCVE AI on October 5, 2026 at 02:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 01:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /Auth/add_student.php of the component Student Registration. The manipulation of the argument cmdschool results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
Title SourceCodester Drug Recommendation System Student Registration add_student.php sql injection
First Time appeared Sourcecodester
Sourcecodester drug Recommendation System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:sourcecodester:drug_recommendation_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester drug Recommendation System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Drug Recommendation System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-05T00:45:15.519Z

Reserved: 2026-10-04T08:50:19.279Z

Link: CVE-2026-105175

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T01:16:28.190

Modified: 2026-10-05T01:16:28.190

Link: CVE-2026-105175

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T03:00:12Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')