Impact
A flaw in the Drug Recommendation System causes the file drug_recommendor.sql to be read and its contents returned to an attacker. The result is an unprotected disclosure of potentially sensitive data. The vulnerability falls under Information Exposure (CWE‑200) and Improper Access Control (CWE‑284).
Affected Systems
The affected product is the SourceCodester Drug Recommendation System, version 1.0. The flaw is triggered when requests reach the path /db/drug_recommendor.sql on the web server, exposing the SQL file owned by the application.
Risk and Exploitability
The CVSS score of 6.9 reflects a moderate severity and the EPSS of less than 1 % indicates a very low chance of active exploitation at present. The vulnerability is not listed as a known exploited vulnerability by CISA. Attackers can carry out the exploit remotely once the public exploit scripts are available, potentially exposing confidential data without needing elevated privileges.
OpenCVE Enrichment