Impact
An XSS flaw exists in the Drug Recommendation System 1.0 specifically within the Admin/add_drug.php handler. By manipulating input parameters sent to this file, an attacker can cause arbitrary JavaScript to run in the victim’s browser. The vulnerability is related to CWE‑79 (Cross‑Site Scripting) and CWE‑94 (Code Injection).
Affected Systems
The affected product is the SourceCodester Drug Recommendation System, version 1.0. No additional version details are provided in the advisory.
Risk and Exploitability
The CVSS score of 5.3 places the issue in the moderate severity range. The EPSS score is not available, but the vulnerability has been publicly disclosed and an exploit has been released, indicating a realistic risk of exploitation. The attack is remote; an attacker can deliver malicious input or a crafted link to a user, triggering the XSS payload in the user’s browser. The vulnerability is not tracked in the CISA KEV catalog, but it remains a concern for any deployment of the affected version.
OpenCVE Enrichment