CVE-2026-105175: SourceCodester Drug Recommendation System Student Registration add_student.php sql injection
A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /Auth/addstudent.php of the component Student Registration. The manipulation of the argument cmdschool results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The attack can be executed remotely and requires no privileges or user interaction according to the supplied vector. An attacker can target the Student Registration functionality through the affected /Auth/add_student.php endpoint.
What input is affected?
The SQL injection is triggered by manipulation of the cmdschool argument in the Student Registration component. The available information identifies SourceCodester Drug Recommendation System version 1.0 as affected.
How urgent is remediation?
The issue is rated high with a 7.3 severity score, and public exploit information is available. Its vector indicates potential low-impact compromise of confidentiality, integrity, and availability.