Description
A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This impacts an unknown function of the file Admin/add_drug.php. Performing a manipulation results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
Published: 2026-10-06
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting
Action: Patch Now
AI Analysis

Impact

An XSS flaw exists in the Drug Recommendation System 1.0 specifically within the Admin/add_drug.php handler. By manipulating input parameters sent to this file, an attacker can cause arbitrary JavaScript to run in the victim’s browser. The vulnerability is related to CWE‑79 (Cross‑Site Scripting) and CWE‑94 (Code Injection).

Affected Systems

The affected product is the SourceCodester Drug Recommendation System, version 1.0. No additional version details are provided in the advisory.

Risk and Exploitability

The CVSS score of 5.3 places the issue in the moderate severity range. The EPSS score is not available, but the vulnerability has been publicly disclosed and an exploit has been released, indicating a realistic risk of exploitation. The attack is remote; an attacker can deliver malicious input or a crafted link to a user, triggering the XSS payload in the user’s browser. The vulnerability is not tracked in the CISA KEV catalog, but it remains a concern for any deployment of the affected version.

Generated by OpenCVE AI on October 6, 2026 at 05:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the application to a patched version when it becomes available.
  • If an update is unavailable, remove or strongly restrict public access to the Admin/add_drug.php endpoint by implementing authentication and role‑based access controls.
  • Sanitize all user‑supplied input and validate input data types before processing or displaying them.
  • Use output encoding (e.g., HTML escaping) for data displayed back to the user to prevent script execution.
  • Consider adding a Content Security Policy header to limit the execution of inline scripts and reduce the impact of any XSS that may still exist.

Generated by OpenCVE AI on October 6, 2026 at 05:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 04:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This impacts an unknown function of the file Admin/add_drug.php. Performing a manipulation results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
Title SourceCodester Drug Recommendation System add_drug.php cross site scripting
First Time appeared Sourcecodester
Sourcecodester drug Recommendation System
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:sourcecodester:drug_recommendation_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester drug Recommendation System
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Drug Recommendation System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-06T04:30:16.587Z

Reserved: 2026-10-05T18:23:24.535Z

Link: CVE-2026-105705

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T05:16:37.847

Modified: 2026-10-06T05:16:37.847

Link: CVE-2026-105705

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T06:00:08Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')