CVE-2026-94016: SourceCodester Drug Recommendation System add_symptom cross site scripting
A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This impacts an unknown function of the file /drugrecommender/Admin/addsymptom. Performing a manipulation of the argument txtname results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Instances of SourceCodester Drug Recommendation System 1.0 that expose the /drug_recommender/Admin/add_symptom functionality are affected. Exploitation requires high privileges and user interaction according to the supplied severity vector.
What does an attacker need to exploit it?
An attacker can remotely manipulate the txtname argument handled by /drug_recommender/Admin/add_symptom. The available data indicates low attack complexity, but requires high privileges and a user to interact with the injected content.
Is exploit activity a practical concern?
Yes. A public exploit has been released, so the issue may be used in attacks even though its reported severity is low.