Impact
A remote attacker can manipulate the user_id argument used by the Auth Guard component of SourceCodester Drug Recommendation System, causing the system to authenticate without proper verification. This flaw is classified as improper authentication (CWE-287) and can allow unauthorized users to access protected resources and functions that should be restricted.
Affected Systems
The vulnerability affects SourceCodester Drug Recommendation System version 1.0. The issue is present in the Auth Guard function within that release, and no other versions are listed as affected.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the exploit is remotely executable with publicly available code. EPSS data is not available and the issue is not in the CISA KEV catalog, but the remote nature of the attack and the lack of authentication imply a significant risk to confidentiality and integrity if an unauthenticated user gains access.
OpenCVE Enrichment