Product
SourceCodester Drug Recommendation System 1.0 is vulnerable to remote SQL injection via the ID argument in /Admin/edit_symptom.php, allowing unauthenticated attackers to manipulate backend database queries.