CVE-2025-2869: Reflected Cross-Site Scripting (XSS) vulnerability in Clinic Queuing System
Reflected Cross-Site Scripting (XSS) vulnerability in version 1.0 of the Clinic Queuing System. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the id parameter in /manageuser.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2869?
CVE-2025-2869 is classified as a medium severity vulnerability due to its potential to allow reflected Cross-Site Scripting attacks.
How can I fix CVE-2025-2869?
To fix CVE-2025-2869, update the Clinic Queuing System to the latest version where the XSS vulnerability has been addressed.
What impact does CVE-2025-2869 have on users?
CVE-2025-2869 can potentially allow attackers to execute arbitrary JavaScript in the browser of users accessing the affected system.
Is CVE-2025-2869 easy to exploit?
Yes, CVE-2025-2869 can be easily exploited by sending a crafted URL with malicious payloads via the id parameter.
What environments are affected by CVE-2025-2869?
CVE-2025-2869 affects all installations of version 1.0 of the Clinic Queuing System.