{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/drug-recommendation-system-1.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:sourcecodester:drug_recommendation_system:1.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-93997"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Drug Recommendation System (1.0)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","sqli"],"_cs_type":"advisory","_cs_vendors":["SourceCodester"],"content_html":"\u003cp\u003eA SQL injection vulnerability has been identified in SourceCodester Drug Recommendation System version 1.0. The vulnerability resides within the /Admin/edit_symptom.php script, specifically affecting the handling of the 'ID' argument. This flaw allows remote, unauthenticated attackers to inject arbitrary SQL commands into the backend database. Publicly available exploit code exists, increasing the risk of unauthorized data access, modification, or complete database compromise. Organizations utilizing this software should restrict access to the administrative interface and review all application logs for anomalous SQL patterns originating from the /Admin/ directory.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability permits remote attackers to execute arbitrary SQL queries against the application database. This can lead to the unauthorized disclosure of sensitive medical or system data, modification of existing records, or potentially administrative account takeover. Given the nature of the application as a drug recommendation system, the integrity of the data is critical.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestrict access to the /Admin/ directory to known, authorized IP addresses via web server access control lists.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect anomalous characters in the 'ID' parameter of the edit_symptom.php endpoint.\u003c/li\u003e\n\u003cli\u003eAudit database logs for unusual queries or UNION-based SQL injection patterns associated with the user account running the web application service.\u003c/li\u003e\n\u003cli\u003ePrioritize migration away from legacy, unsupported SourceCodester systems if patching is unavailable.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-20T14:21:29Z","date_published":"2026-09-20T12:21:04Z","id":"https://feed.craftedsignal.io/briefs/2026-09-sourcecodester-sql-injection/","summary":"SourceCodester Drug Recommendation System 1.0 is vulnerable to remote SQL injection via the ID argument in /Admin/edit_symptom.php, allowing unauthenticated attackers to manipulate backend database queries.","title":"SQL Injection in SourceCodester Drug Recommendation System","url":"https://feed.craftedsignal.io/briefs/2026-09-sourcecodester-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Drug Recommendation System (1.0)","version":"https://jsonfeed.org/version/1.1"}