Sceawere
Vulnerability Detail
CVE-2026-105177UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SQL Injection in Drug Recommendation System
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.7
- Creation Date
- 16h ago
- Vendor
- SourceCodester
- Product
- Drug Recommendation System
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. The affected element is an unknown function of the file /Admin/add_drug.php of the component Drug Creation. Such manipulation of the argument txtname/cmdtype/txtusage/txtsideeffect/cmdcontraindication leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.7",
"pubDate": "2026-10-05T02:16:49.670Z",
"pubdate": "2026-10-05T02:16:49.670Z",
"executiveSummary": "A SQL injection vulnerability has been identified within the SourceCodester Drug Recommendation System 1.0. The vulnerability exists within the Drug Creation component, specifically in the /Admin/add_drug.php file. The flaw allows remote, unauthenticated, or authenticated attackers to inject malicious SQL commands through several parameters, including txtname, cmdtype, txtusage, txtsideeffect, and cmdcontraindication.\nThe primary risk involves unauthorized interaction with the underlying database. By manipulating these input fields, an attacker can bypass security controls to execute arbitrary SQL queries, leading to data exfiltration, unauthorized modification, or potential administrative access to the database environment.\nThis vulnerability is classified as critical due to the ease of remote exploitation and the existence of publicly available exploit code. Organizations utilizing this version of the Drug Recommendation System are at risk of complete database compromise if the application lacks adequate input sanitization and parameterized query implementation. Immediate remediation is required to prevent potential malicious activity.",
"technicalDetails": "The root cause of the vulnerability in /Admin/add_drug.php is the failure of the application to properly sanitize or parameterize user-supplied input before incorporating it into database queries within the Drug Creation component.\nThe vulnerability manifests through multiple input vectors: txtname, cmdtype, txtusage, txtsideeffect, and cmdcontraindication. These parameters are processed by the server-side script without sufficient validation against malicious SQL syntax.\nExploitation follows a standard SQL injection pattern: the attacker intercepts the HTTP request associated with the 'add_drug' functionality. By injecting crafted SQL fragments (e.g., using UNION-based, boolean-based, or time-based blind injection techniques) into any of the vulnerable parameters, the attacker forces the database engine to interpret the input as executable code rather than literal data.\nThe attack flow proceeds as follows: 1) The attacker identifies the endpoint /Admin/add_drug.php; 2) The attacker submits a malicious payload via a POST request targeting one of the aforementioned parameters; 3) The server-side script constructs a SQL query concatenated with the tainted input; 4) The database executes the resulting malicious query; 5) The attacker observes the response or outcome to extract data, manipulate existing records, or escalate privileges.\nBecause the input is not handled via prepared statements (parameterized queries), the database engine cannot distinguish between the developer's intended query logic and the attacker's injected instructions. This allows for arbitrary command execution within the context of the database user account defined in the application configuration.\nThe impact of a successful exploitation is severe. Depending on the database permissions assigned to the web application's service account, an attacker may perform unauthorized data retrieval (e.g., sensitive drug information or user records), modify or delete data, or even perform administrative tasks within the database management system. Given the public availability of exploit code, the barrier to entry for potential attackers is significantly reduced, necessitating immediate focus on input validation and architectural changes to secure the database layer."
}