PT-2026-95978 · Sourcecodester · Drug Recommendation System

·

CVE-2026-94035

·

Published

2026-09-20

·

Updated

2026-09-24

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions SourceCodester Drug Recommendation System version 1.0
Description Cross site scripting (XSS) occurs when an application includes untrusted data in a web page without proper validation or escaping, allowing an attacker to execute malicious scripts in the victim's browser. A remote attack is possible through the manipulation of the full name argument within the /drug recommender/index.php endpoint.
Recommendations Update SourceCodester Drug Recommendation System version 1.0 to a version that contains a fix for this issue. As a temporary workaround, restrict access to the /drug recommender/index.php endpoint or sanitize the full name input to minimize the risk of exploitation.

Exploit

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94035

Affected Products

Drug Recommendation System