CVE-2026-105705: SourceCodester Drug Recommendation System add_drug.php cross site scripting
A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This impacts an unknown function of the file Admin/adddrug.php. Performing a manipulation results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
Can this be exploited remotely without authentication?
The vulnerability is described as remotely exploitable and requires no privileges. Exploitation does require user interaction, consistent with cross-site scripting attacks that rely on a victim viewing or interacting with malicious content.
Is there public exploit information available?
Yes. The available data states that an exploit has been publicly released and may be used in attacks.
What product version is known to be affected?
The affected product is SourceCodester Drug Recommendation System version 1.0. The issue involves an unknown function in Admin/add_drug.php.