medium · CVSS v3 5.3 · CVSS v4 6.9
CVE-2026-92927
An information disclosure vulnerability exists in SourceCodester Drug Recommendation System 1.0 within the drug_recommendor.sql file process
Overview
An information disclosure vulnerability exists in SourceCodester Drug Recommendation System 1.0 within the drug_recommendor.sql file processing. Remote attackers can leverage this flaw to access sensitive database information. Addressing this exposure is vital to prevent the leakage of internal application data.
Description
A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /db/drug_recommendor.sql. Performing a manipulation results in information disclosure. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
Impact
This vulnerability impacts the confidentiality of the database contents stored within the system. Unauthorized remote actors can view sensitive data without requiring authentication. Administrators and users of the deployment are directly affected by the potential exposure of system records. Integrity and availability remain unaffected by this specific flaw.
Remediation
Restrict direct public access to database backup and SQL dump files via web server configuration rules. Implement proper access controls on sensitive scripts and endpoints. Review application directories to ensure no residual database setup files are left exposed to the internet. Upgrade the software or apply vendor-supplied patches if available.
Risk context
The vulnerability is rated as medium severity with a CVSS v3 score of 5.3 and CVSS v4 score of 6.9, indicating moderate risk. Although an exploit has been made public, EPSS data is currently unavailable. Remediation should be prioritized based on the exposure of the affected server to untrusted networks.
Affected products
- SourceCodester Drug Recommendation System 1.0
Scores
- Severity
- medium
- CVSS v2
- 5
- CVSS v3
- 5.3
- CVSS v4
- 6.9
- EPSS
- —