Executive brief
SourceCodester Drug Recommendation System is a web application used for medical drug recommendations. A stored cross-site scripting vulnerability in the user profile allows attackers to inject malicious code that executes when other users view the dashboard, potentially enabling account takeover, session hijacking, or credential theft from affected users.
Technical details
A stored XSS vulnerability exists in the /drug_recommender/profile endpoint where the full name parameter is accepted without proper input sanitization or output encoding. The malicious payload is persisted in the database and executed in the context of users' browser sessions when rendered on /drug_recommender/index.php. This requires authentication to inject but affects any user who views the dashboard containing the stored payload.
Affected products
- SourceCodester Drug Recommendation System 1.0
Timeline
- 2026-09-20: disclosed
- 2026-09-20: advisory: CVE-2026-94035 assigned