Description
A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected by this issue is some unknown functionality of the file /Admin/edit_symptom.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
Published: 2026-09-20
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL injection that may expose or alter database data
Action: Apply Patch
AI Analysis

Impact

SourceCodester Drug Recommendation System 1.0 has a flaw in the /Admin/edit_symptom.php script. By manipulating the ID parameter, an attacker can inject malicious SQL. This injection is executable remotely and the exploit has already been made publicly available, allowing attackers to read or modify data stored in the database.

Affected Systems

Only SourceCodester Drug Recommendation System version 1.0 is listed as affected. No other product versions appear to be impacted according to the CNA data.

Risk and Exploitability

The CVSS score of 6.9 indicates medium severity. No EPSS score is provided and the vulnerability is not listed in CISA KEV, suggesting it is not known to be actively exploited in the wild yet. Nevertheless, the remote nature of the attack and public availability of the exploit mean that anyone with network access could potentially compromise the system, affecting data confidentiality and integrity.

Generated by OpenCVE AI on September 20, 2026 at 12:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to the latest release of SourceCodester Drug Recommendation System once the vendor releases a patch that eliminates the SQL injection issue.
  • If a patch is not available, refactor the /Admin/edit_symptom.php code to use parameterized queries or prepared statements and validate the ID parameter so that only numeric values are accepted.
  • Ensure that the /Admin interface is protected by strong authentication and role‑based access control, and consider adding WAF rules that block suspicious SQL patterns.

Generated by OpenCVE AI on September 20, 2026 at 12:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected by this issue is some unknown functionality of the file /Admin/edit_symptom.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
Title SourceCodester Drug Recommendation System edit_symptom.php sql injection
First Time appeared Sourcecodester
Sourcecodester drug Recommendation System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:sourcecodester:drug_recommendation_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester drug Recommendation System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Drug Recommendation System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T07:44:59.051Z

Reserved: 2026-09-19T13:23:42.308Z

Link: CVE-2026-93997

cve-icon Vulnrichment

Updated: 2026-09-21T14:24:16.828Z

cve-icon NVD

Status : Deferred

Published: 2026-09-20T12:17:05.217

Modified: 2026-09-21T15:17:37.393

Link: CVE-2026-93997

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T13:00:11Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')