CVE-2026-3171: SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System queue.php cross site scripting
A flaw has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /queue.php. This manipulation of the argument firstname/lastname causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3171?
CVE-2026-3171 is classified as a cross-site scripting vulnerability, which can lead to the execution of malicious scripts in the user’s browser.
How do I fix CVE-2026-3171?
To fix CVE-2026-3171, you should sanitize and validate user inputs in the /queue.php file to prevent injection of malicious scripts.
Which software is affected by CVE-2026-3171?
CVE-2026-3171 affects the SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System version 1.0.
What are the potential impacts of CVE-2026-3171?
The potential impacts of CVE-2026-3171 include unauthorized access to user sessions and data theft through executed malicious scripts.
How can I determine if my system is vulnerable to CVE-2026-3171?
You can determine if your system is vulnerable to CVE-2026-3171 by checking if you are using the affected version of the SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System and assessing user input handling in /queue.php.