---
id: CVE-2026-94033
title: >-
  A vulnerability has been found in SourceCodester Drug Recommendation System
  1.0
summary: >-
  A vulnerability has been found in SourceCodester Drug Recommendation System
  1.0. This vulnerability affects unknown code of the file
  /drug_recommender/Admin/add_user of the component User Management. Such
  manipulation of the argument txt…
severity: low
cvss: 3.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
  - CWE-94
vendor: SourceCodester
product: Drug Recommendation System
affected:
  - drug_recommendation_system 1.0
published: '2026-09-20'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T21:17:21.147'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94033'
references:
  - url: >-
      https://github.com/KaranParelkar/Drug_recommendation_system/blob/main/xss/add_user/Readme.md
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-94033'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/946133'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/407961'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/407961/cti'
    label: cna@vuldb.com
  - url: 'https://www.sourcecodester.com/'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00203
epssPercentile: 0.10539
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-21T20:09:41.744241Z'
ingestedAt: '2026-09-20T15:23:06.852Z'
---

## Overview

A vulnerability has been found in SourceCodester Drug Recommendation System 1.0. This vulnerability affects unknown code of the file /drug_recommender/Admin/add_user of the component User Management. Such manipulation of the argument txtname/txtemail/txtpassword leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
