CVE-2026-105179

Summary

A weakness has been identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the file Admin/add_user.php of the component Password Handler. Executing a manipulation of the argument Password can lead to missing encryption of sensitive data. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.

Affected Software

VendorProductVersion RangeStatus
SourceCodesterDrug Recommendation System1.0affected

Weaknesses

  • CWE-311: Missing Encryption of Sensitive Data
  • CWE-310: Cryptographic Issues

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: partial

References