Sceawere
Vulnerability Detail
CVE-2026-105178UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SQL Injection in Drug Recommendation System
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.7
- Creation Date
- 16h ago
- Vendor
- SourceCodester
- Product
- Drug Recommendation System
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. The impacted element is the function mysqli_real_escape_string of the file /Admin/add_symptom.php of the component Symptom Creation. Performing a manipulation of the argument txtname results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.7",
"pubDate": "2026-10-05T02:16:49.850Z",
"pubdate": "2026-10-05T02:16:49.850Z",
"executiveSummary": "A critical SQL injection vulnerability exists in the Symptom Creation component of the SourceCodester Drug Recommendation System 1.0.\nThe vulnerability originates from improper sanitization of user-supplied input within the '/Admin/add_symptom.php' file.\nSuccessful exploitation allows an unauthenticated or authenticated attacker to inject arbitrary SQL commands into the backend database, potentially leading to unauthorized data disclosure, modification, or total compromise of the database integrity.\nGiven that the exploit is publicly available, the risk to deployments is considered high, as the barrier to entry for exploitation is low and does not require complex infrastructure.\nThe flaw impacts the 'txtname' parameter, which fails to correctly utilize the 'mysqli_real_escape_string' function to neutralize malicious characters.\nThis vulnerability is categorized as a security-critical defect that necessitates immediate remediation to prevent unauthorized database interactions or administrative account takeover.",
"technicalDetails": "The root cause of this vulnerability is improper input validation and sanitization within the 'txtname' parameter handled by '/Admin/add_symptom.php'.\nAlthough the 'mysqli_real_escape_string' function is referenced, it is either implemented incorrectly or bypassed, failing to sanitize the input against malicious SQL syntax.\nThe application processes the 'txtname' input and directly incorporates it into a backend SQL query without utilizing prepared statements or parameterized queries.\nThe attack flow begins when an attacker sends a crafted HTTP request containing malicious SQL payloads within the 'txtname' argument.\nBecause the input is not properly escaped, the database engine interprets the injected strings as executable code rather than literal data.\nThis allows an attacker to manipulate the query structure, effectively altering the logic of the application to execute commands such as 'UNION SELECT', 'OR 1=1', or stacked queries.\nThe exploitation is remote and does not require local access, significantly increasing the attack surface.\nPost-exploitation impact includes the potential to extract sensitive health-related data, bypass authentication mechanisms, or execute administrative commands depending on the database user permissions.\nThe vulnerability is persistent across instances of SourceCodester Drug Recommendation System 1.0 where the '/Admin/add_symptom.php' component is accessible.\nBy leveraging publicly available exploit scripts, an attacker can automate the discovery and dumping of table structures or administrative credentials stored within the database.\nBecause the 'mysqli_real_escape_string' implementation does not effectively mitigate the threat, the application remains vulnerable to standard SQL injection techniques, including time-based and boolean-based blind injection.\nThe lack of robust output encoding or structural query separation renders the application unable to distinguish between legitimate symptom names and malicious SQL commands injected by a threat actor."
}