Impact
The vulnerability resides in an unknown function of the file Admin/add_drug.php in the Drug Creation component of SourceCodester Drug Recommendation System 1.0. By manipulating the arguments txtname, cmdtype, txtusage, txtsideeffect, and cmdcontraindication, an attacker can inject arbitrary SQL code. This flaw is a classic example of SQL injection (CWE-89) combined with data conversion weaknesses (CWE-74). The impact is the potential unauthorized access or modification of the underlying database, leading to loss of confidentiality, integrity, and potentially availability. The exploit is publicly documented and can be performed remotely.
Affected Systems
The affected product is SourceCodester Drug Recommendation System, version 1.0. The specific vulnerability is located in /Admin/add_drug.php, the Drug Creation module. Users running this version without a patch are directly exposed to injection attacks on the exposed CGI parameters.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, but the presence of a publicly available exploit and the ability to perform the attack from a remote host raise the practical risk. An attacker with remote access to the web interface can send crafted payloads to the listed parameters and potentially gain control over database queries, reading or altering mission‑critical data. No additional prerequisites beyond access to the web application are indicated, making this a high‑impact issue for deployments of the unpatched 1.0 release.
OpenCVE Enrichment