CVE-2026-1147: SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System api_patient_schedule.php cross site scripting
A vulnerability was found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. This affects an unknown part of the file /php/apipatientschedule.php. Performing a manipulation of the argument Reason results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1147?
CVE-2026-1147 is classified as a cross-site scripting (XSS) vulnerability.
How do I fix CVE-2026-1147?
To fix CVE-2026-1147, you should sanitize and validate user inputs in the script located at /php/api_patient_schedule.php.
What components are affected by CVE-2026-1147?
CVE-2026-1147 affects the SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System version 1.0.
What type of attack can be executed through CVE-2026-1147?
CVE-2026-1147 allows attackers to execute arbitrary JavaScript code in the victim's browser via cross-site scripting.
Is CVE-2026-1147 publicly disclosed?
Yes, CVE-2026-1147 has been publicly disclosed and is listed in the CVE database.