PT-2026-95977 · Sourcecodester · Drug Recommendation System

·

CVE-2026-94034

·

Published

2026-09-20

·

Updated

2026-09-20

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions SourceCodester Drug Recommendation System version 1.0
Description An issue exists in the Password Change component within the file '/drug recommender/Admin/change password'. Remote attackers can perform cross-site scripting (XSS)—a technique used to inject malicious scripts into web pages viewed by other users—by manipulating the txtoldpassword and txtnewpassword variables.
Recommendations Update SourceCodester Drug Recommendation System version 1.0 to a version that addresses this issue. As a temporary mitigation, restrict access to the '/drug recommender/Admin/change password' endpoint.

Exploit

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94034

Affected Products

Drug Recommendation System