Sceawere

Vulnerability Detail

CVE-2026-105175UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SQL Injection in Drug Recommendation System

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
17h ago
Vendor
SourceCodester
Product
Drug Recommendation System
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /Auth/add_student.php of the component Student Registration. The manipulation of the argument cmdschool results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-10-05T01:16:28.190Z",
  "pubdate": "2026-10-05T01:16:28.190Z",
  "executiveSummary": "A SQL injection vulnerability has been identified within the Student Registration component of SourceCodester Drug Recommendation System 1.0.\nThe vulnerability resides in the /Auth/add_student.php file, specifically within the handling of the cmdschool argument.\nThe flaw allows a remote, unauthenticated attacker to manipulate backend database queries by injecting arbitrary SQL commands through the input parameter.\nSuccessful exploitation poses a critical risk, enabling unauthorized access to sensitive student records, data modification, or complete database compromise.\nThe vulnerability is currently public, significantly increasing the probability of exploitation by threat actors.\nThe attack is executable remotely over the network, requiring no prior authentication, and impacts the integrity and confidentiality of the underlying database management system.",
  "technicalDetails": "The vulnerability is a classic SQL injection (SQLi) flaw occurring within the server-side processing logic of /Auth/add_student.php in the Student Registration module.\nRoot cause analysis indicates that the application fails to perform adequate input validation or sanitization on the cmdschool argument before incorporating it into a database query string.\nWhen a user submits data to this endpoint, the provided value for cmdschool is concatenated directly into a SQL statement executed against the database. Because the application does not utilize parameterized queries or prepared statements, an attacker can supply crafted input containing SQL control characters to alter the intended logic of the query.\nThe attack flow begins with the adversary identifying the /Auth/add_student.php endpoint. The attacker then transmits an HTTP request (typically via GET or POST) where the cmdschool parameter is injected with malicious SQL syntax. For example, by including characters such as single quotes ('), semicolons (;), or comment indicators (--, #), the attacker can terminate the original query and append additional commands.\nUpon processing the request, the database management system executes the injected payload with the privileges of the database user account utilized by the application. This allows for unauthorized operations such as exfiltrating the entire database structure, dumping sensitive user credentials, modifying stored records, or, depending on the database configuration, potentially executing system-level commands if the database service is improperly hardened.\nThis vulnerability is classified as remotely exploitable, as the target file is accessible over the network without requiring authentication. Since the exploit code is public, the complexity of crafting a successful attack is significantly lowered, facilitating potential automated exploitation by unauthorized parties.\nImpact includes a complete breach of data confidentiality and integrity, as the application fails to enforce boundaries between user-controlled data and command execution."
}
CVE-2026-105175: SQL Injection in Drug Recommendation System (HIGH Severity, CVSS: 7.3) | Sceawere