CVE-2026-105176: SourceCodester Drug Recommendation System edit_class.php sql injection
A vulnerability was determined in SourceCodester Drug Recommendation System 1.0. Impacted is an unknown function of the file /Admin/editclass.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The available data indicates that exploitation requires high privileges (PR:H). The vulnerable endpoint is remotely reachable, but the data does not establish that unauthenticated or low-privileged users can exploit it.
Is there evidence that exploitation is practical?
Yes. The exploit has been publicly disclosed and is reported as potentially usable. The CVSS vector also rates attack complexity as low.
Which component should be investigated?
Investigate the handling of the ID argument in /Admin/edit_class.php in SourceCodester Drug Recommendation System 1.0. The reported weakness is SQL injection in an unspecified function of that file.