CVE-2026-105705
Received Received - Intake

Cross-Site Scripting in Drug Recommendation System 1.0

Vulnerability report for CVE-2026-105705, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: VulDB

Description

A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This impacts an unknown function of the file Admin/add_drug.php. Performing a manipulation results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
SourceCodester Drug Recommendation System 1.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Cross-Site Scripting (XSS) flaw in the Drug Recommendation System 1.0. It involves improper handling of user input in the Admin/add_drug.php file, allowing attackers to inject malicious scripts. The attack can be executed remotely and has a public exploit available.

Detection Guidance

To detect this XSS vulnerability, inspect web application inputs like form fields in Admin/add_drug.php for improperly encoded user input. Check if malicious scripts execute when input is reflected or stored. Use browser developer tools to monitor network requests and responses for unencoded data. Test with payloads like <script>alert(1)</script> in input fields.

  • Check HTTP responses for unencoded user input in HTML attributes or body text.
  • Use tools like Burp Suite or OWASP ZAP to intercept and modify requests, testing for XSS payload execution.
Impact Analysis

An attacker could exploit this to execute scripts in the context of an authenticated admin, leading to session theft, phishing attacks, or persistent unauthorized access. The impact includes potential data breaches and compromised user accounts.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Non-compliance may result in legal penalties and reputational damage.

Mitigation Strategies

Implement context-aware output encoding using functions like htmlspecialchars to escape user input. Enforce strict input validation to reject or sanitize malicious scripts. Set secure cookie policies (HttpOnly, Secure flags) to prevent session theft. Update the application to the latest patched version if available.

  • Apply output encoding before rendering user-controlled data in HTML, JavaScript, or attributes.
  • Restrict admin pages to authenticated users only and limit input lengths to reduce attack surface.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105705. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart