CVE-2026-105179: medium-severity vulnerability in SourceCodester Drug Recommendation System
SourceCodester Drug Recommendation System Password add_user.php missing encryption
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.1epss 0.2%
exploitation probability
0.2%top 96% of all CVEs
observed exploitation
nono source reports it
A weakness has been identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the file Admin/add_user.php of the component Password Handler. Executing a manipulation of the argument Password can lead to missing encryption of sensitive data. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
Affected products
SourceCodester · Drug Recommendation SystemRelated CVEs — SourceCodester Drug Recommendation System
In the same product, most dangerous first.
CVE-2026-92927MEDIUMSourceCodester Drug Recommendation System drug_recommendor.sql information disclosureEPSS 0.5%CVE-2026-94035MEDIUMSourceCodester Drug Recommendation System index.php cross site scriptingEPSS 0.5%CVE-2026-94015MEDIUMSourceCodester Drug Recommendation System edit_user.php sql injectionEPSS 0.4%CVE-2026-93997MEDIUMSourceCodester Drug Recommendation System edit_symptom.php sql injectionEPSS 0.4%CVE-2026-105704MEDIUMSourceCodester Drug Recommendation System Auth Guard improper authenticationEPSS 0.4%CVE-2026-94016MEDIUMSourceCodester Drug Recommendation System add_symptom cross site scriptingEPSS 0.4%