PT-2026-41440 · Codekernel · Rsi Queue Management System

Kislay Kumar

·

Published

2026-05-16

·

Updated

2026-05-16

·

CVE-2020-37240

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Queue Management System 4.0.0 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through user creation fields. Attackers can insert JavaScript payloads in the First Name, Last Name, and Email fields during user creation, which execute when viewing the User List page.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-37240

Affected Products

Rsi Queue Management System