VYPR

patients-waiting-area-queue-management-system

by Sourcecodester

CVEs (7)

  • CVE-2025-64081CriDec 8, 2025
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in /php/api_patient_schedule.php in SourceCodester Patients Waiting Area Queue Management System v1 allows attackers to execute arbitrary SQL commands via the appointmentID parameter.

  • CVE-2025-13248HigNov 16, 2025
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. The impacted element is an unknown function of the file /php/api_patient_schedule.php. This manipulation of the argument appointmentID causes sql injection. The attack can be…

  • CVE-2025-13122HigNov 13, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. The affected element is the function getPatientAppointment of the file /php/api_patient_checkin.php. Performing manipulation of the argument appointmentID results in sql injection.…

  • CVE-2025-63718MedNov 7, 2025
    risk 0.42cvss 6.5epss 0.00

    A SQL injection vulnerability exists in the SourceCodester PQMS (Patient Queue Management System) 1.0 in the api_patient_schedule.php endpoint. The appointmentID parameter is not properly sanitized, allowing attackers to execute arbitrary SQL commands.

  • CVE-2026-1148MedJan 19, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. This vulnerability affects unknown code. Executing a manipulation can lead to cross-site request forgery. It is possible to launch the attack remotely.

  • CVE-2026-1147LowJan 19, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. This affects an unknown part of the file /php/api_patient_schedule.php. Performing a manipulation of the argument Reason results in cross site scripting. It is possible…

  • CVE-2026-1146LowJan 19, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this issue is some unknown functionality of the file /php/api_register_patient.php. Such manipulation of the argument firstName/lastName leads to cross…