Description
A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. The impacted element is the function mysqli_real_escape_string of the file /Admin/add_symptom.php of the component Symptom Creation. Performing a manipulation of the argument txtname results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.
Published: 2026-10-05
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Remote SQL Injection
Action: Patch
AI Analysis

Impact

A flaw exists in the Drug Recommendation System’s add_symptom.php that allows an attacker to manipulate the txtname input that is sanitized insufficiently using mysqli_real_escape_string. This results in a SQL injection vulnerable to unauthorized data access, modification, or deletion. The potential impact includes compromised confidentiality and integrity of the database.

Affected Systems

The vulnerability impacts SourceCodester’s Drug Recommendation System version 1.0. The affected component is the Symptom Creation module within the Admin section. The flaw is present in add_symptom.php where the txtname field is processed.

Risk and Exploitability

With a CVSS score of 5.1, the vulnerability is classified as medium severity. The EPSS score is unavailable, and the issue is not listed in the CISA KEV catalog, suggesting no widespread exploitation recorded yet. However, the description indicates that exploitation can be performed remotely and a public exploit has been released, implying that attackers could exploit the SQL injection from outside the network, especially if the application is exposed to the internet.

Generated by OpenCVE AI on October 5, 2026 at 02:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check for and install any available vendor patch or newer version of the Drug Recommendation System.
  • Sanitize all user-supplied input, especially the txtname field, using proper escaping or prepared statements.
  • Reduce the database account privileges used by the application to only the necessary permissions, limiting the impact of a successful injection.
  • Consider deploying a web application firewall to detect and block injection attempts.

Generated by OpenCVE AI on October 5, 2026 at 02:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 01:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. The impacted element is the function mysqli_real_escape_string of the file /Admin/add_symptom.php of the component Symptom Creation. Performing a manipulation of the argument txtname results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.
Title SourceCodester Drug Recommendation System Symptom Creation add_symptom.php mysqli_real_escape_string sql injection
First Time appeared Sourcecodester
Sourcecodester drug Recommendation System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:sourcecodester:drug_recommendation_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester drug Recommendation System
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Drug Recommendation System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-05T01:30:24.602Z

Reserved: 2026-10-04T08:50:46.484Z

Link: CVE-2026-105178

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T02:16:49.850

Modified: 2026-10-05T02:16:49.850

Link: CVE-2026-105178

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T02:30:08Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')