Description
A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected is an unknown function. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
Published: 2026-10-06
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Cross‑Site Request Forgery
Action: Assess Impact
AI Analysis

Impact

The CVE describes a cross‑site request forgery vulnerability in SourceCodester Drug Recommendation System 1.0. An attacker can trigger state‑changing actions by tricking an authenticated user into issuing a forged request, potentially altering drug recommendations or other protected data. The flaw is caused by a missing CSRF token in an unknown function, as highlighted by CWE‑352 and further exacerbated by inadequate access control, CWE‑862. Because the request can be initiated remotely, the attacker does not need any direct interaction with the target system beyond luring a logged‑in user to another domain.

Affected Systems

Affected systems are the SourceCodester Drug Recommendation System platform, specifically version 1.0. The vulnerability exists in an unspecified function within the application that processes user requests. No patch or version update has been released by the vendor, and the product’s official CPE demonstrates the base version without additional tags, indicating that any instance that runs the default 1.0 install is potentially exposed.

Risk and Exploitability

The CVSS base score of 5.3 places the flaw in the medium range. EPSS score is not available, but public exploit code and vulnerability discussions show that the flaw can be used by attackers. The exploit is possible over the network, and because the vulnerability involves missing CSRF protection, it is likely to be used in phishing or social‑engineering contexts. The flaw is not currently listed in the CISA KEV catalog, so it has not yet been observed in the wild, but the available proof‑of‑concept demonstrates that attackers can abuse it with moderate effort.

Generated by OpenCVE AI on October 6, 2026 at 06:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Add a robust CSRF protection mechanism—such as synchronizer token patterns—to all state‑changing endpoints in the Drug Recommendation System.
  • Enforce strict access‑control checks on protected operations to ensure only authorized users can modify recommendations, mitigating weaker authorization (CWE‑862).
  • Conduct a comprehensive code review and penetration test focused on request handling to confirm that anti‑CSRF tokens are implemented and that no undispatched state changes exist.

Generated by OpenCVE AI on October 6, 2026 at 06:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 05:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected is an unknown function. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
Title SourceCodester Drug Recommendation System cross-site request forgery
First Time appeared Sourcecodester
Sourcecodester drug Recommendation System
Weaknesses CWE-352
CWE-862
CPEs cpe:2.3:a:sourcecodester:drug_recommendation_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester drug Recommendation System
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Drug Recommendation System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-06T04:45:12.325Z

Reserved: 2026-10-05T18:23:43.366Z

Link: CVE-2026-105706

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T05:16:38.010

Modified: 2026-10-06T05:16:38.010

Link: CVE-2026-105706

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T07:00:12Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)

  • CWE-862

    Missing Authorization