CVE-2026-105179: falha de média gravidade em SourceCodester Drug Recommendation System
SourceCodester Drug Recommendation System Password add_user.php missing encryption
Publicada em
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 5.1epss 0.2%
probabilidade de exploração
0.2%top 96% das CVEs
exploração observada
nãonenhuma fonte reporta
A weakness has been identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the file Admin/add_user.php of the component Password Handler. Executing a manipulation of the argument Password can lead to missing encryption of sensitive data. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
Produtos afetados
SourceCodester · Drug Recommendation SystemCVEs relacionadas — SourceCodester Drug Recommendation System
No mesmo produto, das mais perigosas para as menos.
CVE-2026-92927MEDIUMSourceCodester Drug Recommendation System drug_recommendor.sql information disclosureEPSS 0.5%CVE-2026-94035MEDIUMSourceCodester Drug Recommendation System index.php cross site scriptingEPSS 0.5%CVE-2026-94015MEDIUMSourceCodester Drug Recommendation System edit_user.php sql injectionEPSS 0.4%CVE-2026-93997MEDIUMSourceCodester Drug Recommendation System edit_symptom.php sql injectionEPSS 0.4%CVE-2026-105704MEDIUMSourceCodester Drug Recommendation System Auth Guard improper authenticationEPSS 0.4%CVE-2026-94016MEDIUMSourceCodester Drug Recommendation System add_symptom cross site scriptingEPSS 0.4%