CVE-2026-105179
Received Received - Intake

Missing Password Encryption in Drug Recommendation System 1.0

Vulnerability report for CVE-2026-105179, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: VulDB

Description

A weakness has been identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the file Admin/add_user.php of the component Password Handler. Executing a manipulation of the argument Password can lead to missing encryption of sensitive data. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sourcecodester drug_recommendation_system 1.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-311 The product does not encrypt sensitive or critical information before storage or transmission.
CWE-310 Cryptographic Issues

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Drug Recommendation System 1.0, specifically in the Admin/add_user.php file. It involves a weakness in the password handling component where sensitive data is not properly encrypted. An attacker can remotely manipulate the password argument to exploit this issue.

Detection Guidance

This vulnerability involves missing encryption of sensitive data in the Password field of Admin/add_user.php. To detect it, inspect network traffic for unencrypted password transmissions using tools like Wireshark or tcpdump. Check if the application sends passwords in plaintext via HTTP requests.

Impact Analysis

The vulnerability allows attackers to access sensitive data due to missing encryption. This could lead to unauthorized access to user information, including passwords or personal details. The public availability of an exploit increases the risk of real-world attacks.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA requirements for protecting sensitive data. GDPR mandates encryption for personal data, while HIPAA requires safeguards for protected health information. Failure to encrypt data could result in non-compliance and legal penalties.

Mitigation Strategies

Immediately update or patch the Drug Recommendation System to the latest version to address the missing encryption in the Password Handler component. Review and enforce strong password policies and ensure sensitive data is encrypted during transmission and storage.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105179. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart