CVE-2026-94033: SourceCodester Drug Recommendation System User Management add_user cross site scripting
A vulnerability has been found in SourceCodester Drug Recommendation System 1.0. This vulnerability affects unknown code of the file /drugrecommender/Admin/adduser of the component User Management. Such manipulation of the argument txtname/txtemail/txtpassword leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs low-level privileges and user interaction to exploit it. The attack can be launched remotely, and the affected functionality is the User Management add_user endpoint.
Which inputs are implicated?
The vulnerable endpoint is /drug_recommender/Admin/add_user. The affected arguments are txtname, txtemail, and txtpassword.
Is public exploit information available?
Yes. The exploit has been publicly disclosed and may be used.