Sourcecodester · Drug Recommendation System · CVE-2026-93997
**Name of the Vulnerable Software and Affected Versions**
SourceCodester Drug Recommendation System version 1.0
**Description**
A SQL injection flaw exists in the `/Admin/edit symptom.php` endpoint. This issue occurs when the `ID` argument is manipulated, allowing a remote attacker to execute arbitrary SQL commands.
**Recommendations**
Update SourceCodester Drug Recommendation System to a version newer than 1.0.
As a temporary mitigation, restrict access to the `/Admin/edit symptom.php` file.