Sceawere
Vulnerability Detail
CVE-2026-105179UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Cleartext Password Storage Vulnerability
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 2.7
- Creation Date
- 16h ago
- Vendor
- SourceCodester
- Product
- Drug Recommendation System
- Attack Type
- Missing Encryption of Sensitive Data
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A weakness has been identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the file Admin/add_user.php of the component Password Handler. Executing a manipulation of the argument Password can lead to missing encryption of sensitive data. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "2.7",
"pubDate": "2026-10-05T02:16:50.033Z",
"pubdate": "2026-10-05T02:16:50.033Z",
"executiveSummary": "A critical security weakness exists within the SourceCodester Drug Recommendation System 1.0, specifically impacting the Password Handler component.\nThe vulnerability involves the failure to implement cryptographic hashing or secure encryption for user passwords processed through the Admin/add_user.php file.\nThis flaw results in sensitive credential data being stored in a cleartext format within the underlying database.\nThe vulnerability is remotely exploitable, allowing an unauthorized actor to gain access to stored credentials if they can access the database or manipulate the input vector.\nGiven that public exploit code is available, the risk to the confidentiality and integrity of the administrative user base is high.\nImpact includes complete account takeover and potential escalation of privileges if administrative credentials are recovered.\nImmediate remediation is required to ensure that all authentication secrets are properly salted and hashed using modern cryptographic primitives.",
"technicalDetails": "The vulnerability originates from insecure input handling within the Password Handler component of the SourceCodester Drug Recommendation System 1.0. Specifically, the processing logic located in Admin/add_user.php fails to apply industry-standard cryptographic hashing functions (such as Argon2, bcrypt, or scrypt) to the 'Password' argument before persistence.\nThe root cause is the reliance on plaintext storage or insufficient obfuscation when passing the user-supplied password string from the administrative registration form to the database insertion query. Because the application processes this input without cryptographic transformation, the password remains in its original form upon arrival at the database layer.\nThe attack flow follows a direct manipulation pattern. An attacker interacting with the Admin/add_user.php endpoint can provide arbitrary password strings. Since the application does not validate or transform these strings into secure hash representations, the database retains the password in plaintext. If an attacker gains unauthorized access to the database via SQL injection, misconfigured backup files, or unauthorized server access, they can exfiltrate the full credential set without needing to perform time-intensive cracking procedures.\nThis vulnerability is remotely exploitable, meaning the attacker does not require physical access to the server infrastructure. The exploitability is further exacerbated by the existence of public exploit scripts targeting this specific implementation. Upon successful exploitation, an attacker gains the ability to compromise any user account, including administrative accounts, which typically possess elevated privileges within the system.\nPost-exploitation, the impact is severe. An attacker possessing plaintext passwords can move laterally across other systems if users employ password reuse, a common behavior among administrators. Furthermore, because the vulnerability exists within an administrative management module, the compromise allows for the persistent maintenance of a backdoor, as the attacker can manipulate existing user roles or create new privileged accounts undetected, effectively maintaining control over the Drug Recommendation System environment."
}