CVE-2026-94035: SourceCodester Drug Recommendation System index.php cross site scripting
A vulnerability was determined in SourceCodester Drug Recommendation System 1.0. Impacted is an unknown function of the file /drugrecommender/index.php. Executing a manipulation of the argument full name can lead to cross site scripting. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
An attacker can launch the attack remotely and does not need privileges, but exploitation requires a user to interact with attacker-controlled content or a crafted request. The vulnerable input is the "full name" argument handled by /drug_recommender/index.php.
What is the practical impact of successful exploitation?
Successful exploitation can compromise the integrity of content in the affected user's browser through cross-site scripting. The supplied severity vector indicates no direct confidentiality or availability impact.
Is exploitation theoretical?
No. A public exploit has been disclosed and may be used by attackers.