medium · CVSS v3 3.5 · CVSS v4 5.1
CVE-2026-94034
A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing o…
Description
A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /drug_recommender/Admin/change_password of the component Password Change. Performing a manipulation of the argument txtoldpassword/txtnewpassword results in cross site scripting. The attack can be initiated remotely. The exploit has been made public and could be used.
Scores
- Severity
- medium
- CVSS v2
- 4
- CVSS v3
- 3.5
- CVSS v4
- 5.1
- EPSS
- —