PT-2026-6977 · Sourcecodester · Patients Waiting Area Queue Management System
Webray.Com.Cn
·
Published
2026-02-08
·
Updated
2026-02-08
·
CVE-2026-2150
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System version 1.0
Description
A flaw exists in the Patients Waiting Area Queue Management System that allows for cross site scripting. This manipulation occurs through the
patient id argument in the /checkin.php file and can be initiated remotely. The exploit has been published.Recommendations
Apply any available updates or patches for the Patients Waiting Area Queue Management System.
As a temporary workaround, consider restricting access to the /checkin.php file.
Sanitize the
patient id input to prevent the injection of malicious scripts.Exploit
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Patients Waiting Area Queue Management System