Low severity3.5NVD Advisory· Published Jan 19, 2026· Updated Jun 17, 2026
CVE-2026-1147
CVE-2026-1147
Description
A vulnerability was found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. This affects an unknown part of the file /php/api_patient_schedule.php. Performing a manipulation of the argument Reason results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
Affected products
2- cpe:2.3:a:pamzey:patients_waiting_area_queue_management_system:1.0:*:*:*:*:*:*:*
- Range: = 1.0
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.