Description
A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. The affected element is an unknown function of the file /Admin/add_drug.php of the component Drug Creation. Such manipulation of the argument txtname/cmdtype/txtusage/txtsideeffect/cmdcontraindication leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.
Published: 2026-10-05
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Remote SQL Injection
Action: Patch or Mitigate
AI Analysis

Impact

The vulnerability resides in an unknown function of the file Admin/add_drug.php in the Drug Creation component of SourceCodester Drug Recommendation System 1.0. By manipulating the arguments txtname, cmdtype, txtusage, txtsideeffect, and cmdcontraindication, an attacker can inject arbitrary SQL code. This flaw is a classic example of SQL injection (CWE-89) combined with data conversion weaknesses (CWE-74). The impact is the potential unauthorized access or modification of the underlying database, leading to loss of confidentiality, integrity, and potentially availability. The exploit is publicly documented and can be performed remotely.

Affected Systems

The affected product is SourceCodester Drug Recommendation System, version 1.0. The specific vulnerability is located in /Admin/add_drug.php, the Drug Creation module. Users running this version without a patch are directly exposed to injection attacks on the exposed CGI parameters.

Risk and Exploitability

The CVSS score of 5.1 indicates a moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, but the presence of a publicly available exploit and the ability to perform the attack from a remote host raise the practical risk. An attacker with remote access to the web interface can send crafted payloads to the listed parameters and potentially gain control over database queries, reading or altering mission‑critical data. No additional prerequisites beyond access to the web application are indicated, making this a high‑impact issue for deployments of the unpatched 1.0 release.

Generated by OpenCVE AI on October 5, 2026 at 02:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any vendor‑released patch or upgrade to the latest version of the Drug Recommendation System that eliminates the vulnerable add_drug.php code.
  • Refactor the application to use prepared statements or ORM mechanisms to avoid raw SQL concatenation for parameters txtname, txtusage, txtsideeffect, cmdcontraindication, and cmdtype.
  • Enforce strict input validation or whitelisting for all user‑supplied arguments that reach the database layer.
  • As a temporary measure, configure a web application firewall or intrusion detection system rule to detect and block common SQL injection payloads targeting the /Admin/add_drug.php endpoint.

Generated by OpenCVE AI on October 5, 2026 at 02:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 01:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. The affected element is an unknown function of the file /Admin/add_drug.php of the component Drug Creation. Such manipulation of the argument txtname/cmdtype/txtusage/txtsideeffect/cmdcontraindication leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.
Title SourceCodester Drug Recommendation System Drug Creation add_drug.php sql injection
First Time appeared Sourcecodester
Sourcecodester drug Recommendation System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:sourcecodester:drug_recommendation_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester drug Recommendation System
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Drug Recommendation System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-05T01:15:14.796Z

Reserved: 2026-10-04T08:50:35.339Z

Link: CVE-2026-105177

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T02:16:49.670

Modified: 2026-10-05T02:16:49.670

Link: CVE-2026-105177

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T02:30:08Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')