5.1
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
Description
A vulnerability has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this issue is some unknown functionality of the file /php/api_register_patient.php. Such manipulation of the argument firstName/lastName leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.
Basic Information
ID
CVE-2026-1146
Source
VulDB
Published
Jan 19, 2026 at 08:32
Affected Product
Vendor
SourceCodester
Product
Patients Waiting Area Queue Management System
Version
1.0
Affected Versions
SourceCodester Patients Waiting Area Queue Management System 1.0
Patrick Mvuma Patients Waiting Area Queue Management System 1.0
Patrick Mvuma Patients Waiting Area Queue Management System 1.0