Impact
A vulnerability in the Drug Recommendation System’s add_symptom feature allows an attacker to inject malicious script code through the txtname argument. By manipulating this parameter, an attacker can execute browser code in the context of other users who view the affected page, potentially leading to session hijacking, data theft, or phishing. The flaw is a classic reflected XSS flaw, classified as CWE‑79, and the presence of CWE‑94 indicates possible code injection concerns as well.
Affected Systems
SourceCodester’s Drug Recommendation System version 1.0 is affected. The vulnerability resides in the /drug_recommender/Admin/add_symptom file and impacts any deployment of that product version.
Risk and Exploitability
The CVSS score of 4.8 rates the vulnerability as moderate in severity. No EPSS score is currently available, and the flaw is not listed in CISA’s KEV catalog, though the public exploit release suggests that attackers can already leverage it remotely via crafted web requests.
OpenCVE Enrichment