Impact
A flaw exists in the Drug Recommendation System’s add_symptom.php that allows an attacker to manipulate the txtname input that is sanitized insufficiently using mysqli_real_escape_string. This results in a SQL injection vulnerable to unauthorized data access, modification, or deletion. The potential impact includes compromised confidentiality and integrity of the database.
Affected Systems
The vulnerability impacts SourceCodester’s Drug Recommendation System version 1.0. The affected component is the Symptom Creation module within the Admin section. The flaw is present in add_symptom.php where the txtname field is processed.
Risk and Exploitability
With a CVSS score of 5.1, the vulnerability is classified as medium severity. The EPSS score is unavailable, and the issue is not listed in the CISA KEV catalog, suggesting no widespread exploitation recorded yet. However, the description indicates that exploitation can be performed remotely and a public exploit has been released, implying that attackers could exploit the SQL injection from outside the network, especially if the application is exposed to the internet.
OpenCVE Enrichment