CVE-2026-105704: fallo de gravedad media en SourceCodester Drug Recommendation System
SourceCodester Drug Recommendation System Auth Guard improper authentication
Publicada el
33Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 6.9epss 0.4%
probabilidad de explotación
0.4%top 68% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the component Auth Guard. Such manipulation of the argument user_id leads to improper authentication. The attack can be executed remotely. The exploit is publicly available and might be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Productos afectados
SourceCodester · Drug Recommendation SystemPoCs públicas encontradas — 1
cve_referencegithub.com/hackliu/Vulnerability-Reports/blob/master/Drug-Recommender-Web-App/VULN-02-Broken-Access-Control.mdno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
CVEs relacionadas — SourceCodester Drug Recommendation System
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-92927MEDIUMSourceCodester Drug Recommendation System drug_recommendor.sql information disclosureEPSS 0.5%CVE-2026-94035MEDIUMSourceCodester Drug Recommendation System index.php cross site scriptingEPSS 0.5%CVE-2026-94015MEDIUMSourceCodester Drug Recommendation System edit_user.php sql injectionEPSS 0.4%CVE-2026-93997MEDIUMSourceCodester Drug Recommendation System edit_symptom.php sql injectionEPSS 0.4%CVE-2026-94016MEDIUMSourceCodester Drug Recommendation System add_symptom cross site scriptingEPSS 0.4%CVE-2026-94034MEDIUMSourceCodester Drug Recommendation System Password Change change_password cross site scriptingEPSS 0.3%