Cross Site Scripting Vulnerability in SourceCodester Drug Recommendation System
CVE-2026-94016
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 20 September 2026
Badges
What is CVE-2026-94016?
A security flaw has been identified in the SourceCodester Drug Recommendation System version 1.0, particularly affecting the /drug_recommender/Admin/add_symptom file. The vulnerability arises from improper handling of the 'txtname' argument, allowing attackers to inject malicious scripts, thereby enabling cross site scripting (XSS). This exploit can be executed remotely, potentially affecting users and exposing sensitive information. It is important for users to be aware of this vulnerability and take necessary precautions.
Affected Version(s)
Drug Recommendation System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
