Impact
The CVE describes a cross‑site request forgery vulnerability in SourceCodester Drug Recommendation System 1.0. An attacker can trigger state‑changing actions by tricking an authenticated user into issuing a forged request, potentially altering drug recommendations or other protected data. The flaw is caused by a missing CSRF token in an unknown function, as highlighted by CWE‑352 and further exacerbated by inadequate access control, CWE‑862. Because the request can be initiated remotely, the attacker does not need any direct interaction with the target system beyond luring a logged‑in user to another domain.
Affected Systems
Affected systems are the SourceCodester Drug Recommendation System platform, specifically version 1.0. The vulnerability exists in an unspecified function within the application that processes user requests. No patch or version update has been released by the vendor, and the product’s official CPE demonstrates the base version without additional tags, indicating that any instance that runs the default 1.0 install is potentially exposed.
Risk and Exploitability
The CVSS base score of 5.3 places the flaw in the medium range. EPSS score is not available, but public exploit code and vulnerability discussions show that the flaw can be used by attackers. The exploit is possible over the network, and because the vulnerability involves missing CSRF protection, it is likely to be used in phishing or social‑engineering contexts. The flaw is not currently listed in the CISA KEV catalog, so it has not yet been observed in the wild, but the available proof‑of‑concept demonstrates that attackers can abuse it with moderate effort.
OpenCVE Enrichment