---
id: CVE-2026-94016
title: >-
  A security flaw has been discovered in SourceCodester Drug Recommendation
  System 1.0
summary: >-
  A security flaw has been discovered in SourceCodester Drug Recommendation
  System 1.0. This impacts an unknown function of the file
  /drug_recommender/Admin/add_symptom. Performing a manipulation of the argument
  txtname results in cross si…
severity: low
cvss: 2.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
  - CWE-94
vendor: SourceCodester
product: Drug Recommendation System
affected:
  - drug_recommendation_system 1.0
published: '2026-09-20'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T19:16:58.790'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94016'
references:
  - url: >-
      https://github.com/KaranParelkar/Drug_recommendation_system/blob/main/xss/add_symptom/Readme.md
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-94016'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/944874'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/407956'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/407956/cti'
    label: cna@vuldb.com
  - url: 'https://www.sourcecodester.com/'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00368
epssPercentile: 0.27912
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-22T18:07:58.076675Z'
ingestedAt: '2026-09-20T13:21:45.083Z'
---

## Overview

A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This impacts an unknown function of the file /drug_recommender/Admin/add_symptom. Performing a manipulation of the argument txtname results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
