PT-2026-3430 · Sourcecodester/Patrick Mvuma · Patients Waiting Area Queue Management System

Bobsux

·

Published

2026-01-19

·

Updated

2026-01-19

·

CVE-2026-1147

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System version 1.0
Description A flaw exists in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System version 1.0 that allows for cross site scripting. The issue is located in the file /php/api patient schedule.php. Manipulation of the Reason argument can trigger the flaw, enabling remote attacks. The exploit has been publicly disclosed.
Recommendations Apply any available updates to address this issue. As a temporary workaround, sanitize the Reason input to prevent script injection.

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-1147

Affected Products

Patients Waiting Area Queue Management System