Impact
The vulnerability is an SQL injection that occurs when an attacker manipulates the ID argument in the /Admin/edit_class.php file of SourceCodester Drug Recommendation System 1.0. By supplying a crafted value, the attacker can embed arbitrary SQL commands into the query. This flaw can lead to unauthorized data exposure, modification, or disclosure of the underlying database. The weakness is represented by CWE‑74 and CWE‑89, and the CVSS score is 5.1, indicating a moderate severity. The exploit is remote, publicly disclosed, and does not require local privileges.
Affected Systems
The affected product is SourceCodester Drug Recommendation System version 1.0, particularly the edit_class.php component within the admin interface. No other versions or components are listed as affected by this vulnerability.
Risk and Exploitability
The CVSS score of 5.1 places this flaw in the medium severity range. Because the EPSS score is not available, the exact likelihood of exploitation cannot be quantified, but the disclosure of a remote attack vector and the absence of mitigations in the public release suggest a realistic exploitation opportunity. The vulnerability is not currently listed in the CISA KEV catalog, yet the publicly available exploit code demonstrates that attackers can use it without special tooling. The attack does not require physical or local access, making it a concern for exposed web applications running this system.
OpenCVE Enrichment