Impact
Affected is SourceCodester Drug Recommendation System 1.0, specifically the add_student.php processing. The argument cmdschool is improperly sanitized, allowing attackers to inject arbitrary SQL commands. This can lead to unauthorized data disclosure, modification, or deletion within the system's database. The flaw represents an SQL injection vulnerability (CWE-89) and potentially an input manipulation weakness (CWE-74).
Affected Systems
The product is SourceCodester Drug Recommendation System version 1.0, with the vulnerable file Auth/add_student.php in the Student Registration component. No further sub-version details are provided. Administrators should confirm that their deployed instance uses this version and that the cmdschool parameter remains exposed.
Risk and Exploitability
The CVSS score of 6.9 signals a moderate to high risk level, and the exploit is publicly available, meaning attackers can easily craft malicious requests. EPSS data is not available, but the vulnerability being listed on vulnerability databases indicates it may be actively exploited. This flaw is not yet in CISA KEV, yet it is remotely exploitable as the attacker can submit input from any network location. Attackers could retrieve or corrupt patient or user data, causing integrity or availability damage.
OpenCVE Enrichment