Vulnerabilidad · Publicado 20/09/2026
Se ha identificado una vulnerabilidad de inyección SQL (CVSS 7.3) en SourceCodester Drug Recommendation System 1.0 a través del parámetro ID en /Admin/edit_symptom.php. La vulnerabilidad permite a atacantes remotos ejecutar comandos SQL arbitrarios y comprometer bases de datos de sistemas de salud. El exploit está disponible públicamente, incrementando significativamente el riesgo en instituciones médicas y farmacias en LATAM que utilicen este software.
A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected by this issue is some unknown functionality of the file /Admin/edit_symptom.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
Score: 7.3/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CWE-74, CWE-89
Publicado en NIST NVD.