Impact
A flaw in the password change endpoint of SourceCodester’s Drug Recommendation System allows an attacker to supply malicious JavaScript in the txtoldpassword or txtnewpassword fields. The application reflects the supplied input back into the page response without adequate sanitization, causing the browser to execute the injected code when the page is rendered.
Affected Systems
This vulnerability affects the SourceCodester Drug Recommendation System application, version 1.0. No other products or versions are listed as vulnerable.
Risk and Exploitability
The flaw carries a CVSS score of 5.1, indicating moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. However, the vulnerability is publicly known, an exploit is available, and the attacker can trigger it remotely by sending crafted requests to the /drug_recommender/Admin/change_password endpoint. These conditions make real‑world exploitation a credible threat.
OpenCVE Enrichment