Description
A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /db/drug_recommendor.sql. Performing a manipulation results in information disclosure. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
Published: 2026-09-17
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

A flaw in the Drug Recommendation System causes the file drug_recommendor.sql to be read and its contents returned to an attacker. The result is an unprotected disclosure of potentially sensitive data. The vulnerability falls under Information Exposure (CWE‑200) and Improper Access Control (CWE‑284).

Affected Systems

The affected product is the SourceCodester Drug Recommendation System, version 1.0. The flaw is triggered when requests reach the path /db/drug_recommendor.sql on the web server, exposing the SQL file owned by the application.

Risk and Exploitability

The CVSS score of 6.9 reflects a moderate severity and the EPSS of less than 1 % indicates a very low chance of active exploitation at present. The vulnerability is not listed as a known exploited vulnerability by CISA. Attackers can carry out the exploit remotely once the public exploit scripts are available, potentially exposing confidential data without needing elevated privileges.

Generated by OpenCVE AI on September 19, 2026 at 02:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Restrict web access to the /db/drug_recommendor.sql file or remove it from the document root so it cannot be read by a remote user
  • If the file must remain in place, set filesystem permissions so that only the application owner can read it and the web server user does not have read rights
  • Apply any vendor‑supplied update or patch when released, and monitor official channels for remediation announcements

Generated by OpenCVE AI on September 19, 2026 at 02:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /db/drug_recommendor.sql. Performing a manipulation results in information disclosure. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
Title SourceCodester Drug Recommendation System drug_recommendor.sql information disclosure
First Time appeared Sourcecodester
Sourcecodester drug Recommendation System
Weaknesses CWE-200
CWE-284
CPEs cpe:2.3:a:sourcecodester:drug_recommendation_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester drug Recommendation System
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Drug Recommendation System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T07:43:54.582Z

Reserved: 2026-09-17T11:57:38.088Z

Link: CVE-2026-92927

cve-icon Vulnrichment

Updated: 2026-09-21T21:01:42.750Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T18:17:15.133

Modified: 2026-09-21T21:17:16.770

Link: CVE-2026-92927

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T02:45:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control