Cross-Site Scripting in Patrick Mvuma Patients Waiting Area Queue Management System
CVE-2026-1147
5.1MEDIUM
What is CVE-2026-1147?
A cross-site scripting (XSS) vulnerability exists in the Patrick Mvuma Patients Waiting Area Queue Management System 1.0, particularly in the /php/api_patient_schedule.php file. Attackers can manipulate the 'Reason' argument to execute arbitrary JavaScript in a victim's browser, potentially leading to data theft or session hijacking. This vulnerability can be exploited remotely, making it a considerable risk to users of the system. Publicly available exploits could facilitate actual attacks.
Affected Version(s)
Patients Waiting Area Queue Management System 1.0
Patients Waiting Area Queue Management System 1.0
