216.73.216.197

CVE-2026-1146

· Published 19/01/2026 09:16 · Modified 19/01/2026 09:16

Labels: CVE-2026-1146 2026-01-19CVE-2026-1146CWE-79[email protected]

Essential information

Published
19/01/2026 09:16
Modified
19/01/2026 09:16
Author
Creator
CVSS
5.1 MEDIUM (v3) 5.1 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A vulnerability has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this issue is some unknown functionality of the file /php/api_register_patient.php. Such manipulation of the argument firstName/lastName leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
sourcecodester / patients waiting area queue management system cpe:2.3:a:sourcecodester:patients_waiting_area_queue_management_system:1.0:*:*:*:*:*:*:*

References