Sceawere

Vulnerability Detail

CVE-2026-105178UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SQL Injection in Drug Recommendation System

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.7
Creation Date
16h ago
Vendor
SourceCodester
Product
Drug Recommendation System
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. The impacted element is the function mysqli_real_escape_string of the file /Admin/add_symptom.php of the component Symptom Creation. Performing a manipulation of the argument txtname results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.7",
  "pubDate": "2026-10-05T02:16:49.850Z",
  "pubdate": "2026-10-05T02:16:49.850Z",
  "executiveSummary": "A critical SQL injection vulnerability exists in the Symptom Creation component of the SourceCodester Drug Recommendation System 1.0.\nThe vulnerability originates from improper sanitization of user-supplied input within the '/Admin/add_symptom.php' file.\nSuccessful exploitation allows an unauthenticated or authenticated attacker to inject arbitrary SQL commands into the backend database, potentially leading to unauthorized data disclosure, modification, or total compromise of the database integrity.\nGiven that the exploit is publicly available, the risk to deployments is considered high, as the barrier to entry for exploitation is low and does not require complex infrastructure.\nThe flaw impacts the 'txtname' parameter, which fails to correctly utilize the 'mysqli_real_escape_string' function to neutralize malicious characters.\nThis vulnerability is categorized as a security-critical defect that necessitates immediate remediation to prevent unauthorized database interactions or administrative account takeover.",
  "technicalDetails": "The root cause of this vulnerability is improper input validation and sanitization within the 'txtname' parameter handled by '/Admin/add_symptom.php'.\nAlthough the 'mysqli_real_escape_string' function is referenced, it is either implemented incorrectly or bypassed, failing to sanitize the input against malicious SQL syntax.\nThe application processes the 'txtname' input and directly incorporates it into a backend SQL query without utilizing prepared statements or parameterized queries.\nThe attack flow begins when an attacker sends a crafted HTTP request containing malicious SQL payloads within the 'txtname' argument.\nBecause the input is not properly escaped, the database engine interprets the injected strings as executable code rather than literal data.\nThis allows an attacker to manipulate the query structure, effectively altering the logic of the application to execute commands such as 'UNION SELECT', 'OR 1=1', or stacked queries.\nThe exploitation is remote and does not require local access, significantly increasing the attack surface.\nPost-exploitation impact includes the potential to extract sensitive health-related data, bypass authentication mechanisms, or execute administrative commands depending on the database user permissions.\nThe vulnerability is persistent across instances of SourceCodester Drug Recommendation System 1.0 where the '/Admin/add_symptom.php' component is accessible.\nBy leveraging publicly available exploit scripts, an attacker can automate the discovery and dumping of table structures or administrative credentials stored within the database.\nBecause the 'mysqli_real_escape_string' implementation does not effectively mitigate the threat, the application remains vulnerable to standard SQL injection techniques, including time-based and boolean-based blind injection.\nThe lack of robust output encoding or structural query separation renders the application unable to distinguish between legitimate symptom names and malicious SQL commands injected by a threat actor."
}
CVE-2026-105178: SQL Injection in Drug Recommendation System (MEDIUM Severity, CVSS: 4.7) | Sceawere