Impact
A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. The flaw is in the file /drug_recommender/index.php and arises when an attacker manipulates the full name argument. The input is reflected in the output without proper sanitization, allowing an attacker to inject arbitrary JavaScript that will execute in the victim’s browser. Although the CVE description does not detail the exact downstream effects, cross‑site scripting flaws commonly enable attackers to hijack sessions, phish credentials, or deliver malware – these potential impacts are inferred from the nature of XSS.
Affected Systems
The sole affected product listed is SourceCodester’s Drug Recommendation System version 1.0. No other versions or partner products are enumerated as vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The public disclosure suggests that attackers may exploit the flaw. The attack can be launched remotely by sending a crafted URL that includes a malicious value for the full name parameter. The CVE description does not specify whether authentication is required, so it is unclear whether the attack is restricted to logged‑in users or can affect all visitors.
OpenCVE Enrichment