Impact
SourceCodester Drug Recommendation System 1.0 has a flaw in the /Admin/edit_symptom.php script. By manipulating the ID parameter, an attacker can inject malicious SQL. This injection is executable remotely and the exploit has already been made publicly available, allowing attackers to read or modify data stored in the database.
Affected Systems
Only SourceCodester Drug Recommendation System version 1.0 is listed as affected. No other product versions appear to be impacted according to the CNA data.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity. No EPSS score is provided and the vulnerability is not listed in CISA KEV, suggesting it is not known to be actively exploited in the wild yet. Nevertheless, the remote nature of the attack and public availability of the exploit mean that anyone with network access could potentially compromise the system, affecting data confidentiality and integrity.
OpenCVE Enrichment