CVE-2026-94034
LOW
NVD
CVSS Score
3.5
Severity
LOW
Published
Sep 20, 2026
Vendor
unknown
Description
A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /drug_recommender/Admin/change_password of the component Password Change. Performing a manipulation of the argument txtoldpassword/txtnewpassword results in cross site scripting. The attack can be initiated remotely. The exploit has been made public and could be used.