CVE-2026-105177

Summary

A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. The affected element is an unknown function of the file /Admin/add_drug.php of the component Drug Creation. Such manipulation of the argument txtname/cmdtype/txtusage/txtsideeffect/cmdcontraindication leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.

Affected Software

VendorProductVersion RangeStatus
SourceCodesterDrug Recommendation System1.0affected

Weaknesses

  • CWE-89: SQL Injection
  • CWE-74: Injection

References