Skip to content
Threat Feed
high advisory

SQL Injection Vulnerability in Drug Recommendation System

The Drug Recommendation System 1.0 contains a SQL injection vulnerability in the 'cmdschool' parameter of the student registration module, allowing unauthenticated remote attackers to execute arbitrary database queries.

CVE search metadata

CVE search record: CVE-2026-105175. Severity: high. CVSS: 7.3. KEV: no. Product: Drug Recommendation System (1.0). Brief: SQL Injection Vulnerability in Drug Recommendation System. Brief link: https://feed.craftedsignal.io/briefs/2026-10-drug-recommendation-sqli/

SourceCodester Drug Recommendation System version 1.0 contains a critical SQL injection vulnerability identified as CVE-2026-105175. The flaw resides within the /Auth/add_student.php script, specifically in the processing of the 'cmdschool' parameter within the Student Registration component. Because this parameter is inadequately sanitized before being processed by the backend database, an unauthenticated remote attacker can inject arbitrary SQL commands. Publicly available exploit material exists for this vulnerability, posing a significant risk to organizations using this software. Successful exploitation allows an attacker to manipulate database queries, potentially leading to unauthorized data access, modification, or deletion, depending on the privileges of the database service account.

Impact

The vulnerability allows unauthenticated remote attackers to compromise the backend database associated with the Drug Recommendation System. This could lead to full data exfiltration of sensitive student or system records, integrity loss through unauthorized modifications, or complete database control, which may facilitate further system compromise.

Recommendation

  • Block requests targeting /Auth/add_student.php where the 'cmdschool' parameter contains common SQL injection sequences (e.g., apostrophes, comment characters).
  • Deploy the provided Sigma rule to webserver logs to monitor for exploitation attempts targeting CVE-2026-105175.
  • Audit database permissions for the web application service account to ensure the principle of least privilege is applied, limiting the impact of a successful SQL injection.

Immediate actions

Deploy Sigma rule to webserver logs to monitor for exploitation attempts targeting CVE-2026-105175.

Detection Engineering 24h

Mitigations

Implement WAF or input validation filter to sanitize the 'cmdschool' parameter in /Auth/add_student.php.

immediate IT Operations

CVE-2026-105175

Detection coverage 1

Detects CVE-2026-105175 Exploitation - SQL Injection in Drug Recommendation System

high

Detects attempts to exploit CVE-2026-105175 by monitoring POST/GET requests to add_student.php containing SQL injection characters in the cmdschool parameter.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →