{"id":"CVE-2026-105177","title":"SourceCodester Drug Recommendation System Drug Creation add_drug.php sql injection","summary":"A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. The affected element is an unknown function of the file /Admin/add_drug.php of the component Drug Creation. Such manipulation of the argument txtname/cmdtyp…","severity":"medium","cvss":4.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R","cvssSource":"cna","cwe":["CWE-89","CWE-74"],"vendor":"SourceCodester","product":"Drug Recommendation System","affected":["drug_recommendation_system 1.0"],"published":"2026-10-05","updated":"2026-10-05","sourceUpdated":"2026-10-05T01:15:14.796Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-105177","references":[{"url":"https://vuldb.com/vuln/413409","label":"VDB-413409 | SourceCodester Drug Recommendation System Drug Creation add_drug.php sql injection"},{"url":"https://vuldb.com/vuln/413409/cti","label":"VDB-413409 | CTI Indicators (IOB, IOC, TTP, IOA)"},{"url":"https://vuldb.com/cve/CVE-2026-105177","label":"CVE-2026-105177 | CVE Analysis and Report"},{"url":"https://vuldb.com/submit/970933","label":"Submit #970933 | SourceCodester Drug Recommendation System 1.0 SQL Injection"},{"url":"https://www.sourcecodester.com/"}],"tags":["cve.org"],"ingestedAt":"2026-10-05T02:10:36.197Z","slug":"CVE-2026-105177","body":"## Overview\n\nA vulnerability was identified in SourceCodester Drug Recommendation System 1.0. The affected element is an unknown function of the file /Admin/add_drug.php of the component Drug Creation. Such manipulation of the argument txtname/cmdtype/txtusage/txtsideeffect/cmdcontraindication leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.\n\n## Affected\n\n- `drug_recommendation_system 1.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":26,"depthScoreParts":{"impact":25.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}