CVE-2026-94034: SourceCodester Drug Recommendation System Password Change change_password cross site scripting
A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /drugrecommender/Admin/changepassword of the component Password Change. Performing a manipulation of the argument txtoldpassword/txtnewpassword results in cross site scripting. The attack can be initiated remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker can initiate the attack remotely, but exploitation requires low-level privileges and user interaction. The vulnerable functionality is the administrative password-change component.
Which inputs are involved in the cross-site scripting condition?
The issue is triggered through manipulation of the txtoldpassword and txtnewpassword arguments submitted to /drug_recommender/Admin/change_password.
Is public exploit information available?
Yes. The exploit has been made public and could be used.