Description
A vulnerability was detected in SourceCodester Hospitals Patient Records Management System 1.0. This issue affects some unknown processing of the file /admin/?page=room_types. Performing a manipulation of the argument room results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Published: 2026-06-07
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The reported vulnerability is a cross‑site scripting flaw found in the /admin/?page=room_types endpoint of SourceCodester Hospitals Patient Records Management System. By manipulating the 'room' query parameter, an attacker can inject arbitrary HTML or JavaScript that will be rendered in the browser of a user who views the page. The flaw is remote and requires no special privileges, making it exploitable by anyone that can send a crafted request to the application.

Affected Systems

Affected systems are installations of SourceCodester Hospitals Patient Records Management System version 1.0. The vulnerable code resides in the unvalidated handling of the room parameter and the page rendering logic for room_types. The issue is flagged by the CNA for this specific product and version. No other versions are known to be affected.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Since the attack vector is remote web‑based XSS, the risk is that any authenticated or unauthenticated user who visits the affected page could have malicious script executed in their browser, potentially leading to credential theft, session hijacking, or the delivery of malware. Exploitation is straightforward via a crafted URL, and the public exploit code is currently available.

Generated by OpenCVE AI on June 8, 2026 at 02:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade or apply the vendor‑provided patch for SourceCodester Hospitals Patient Records Management System to a version that sanitizes the room parameter.
  • Ensure that the room parameter is validated and encoded before being included in the response to prevent script injection.
  • Deploy web‑application firewall rules or security headers such as Content‑Security‑Policy and X‑XSS‑Protection to mitigate script execution.

Generated by OpenCVE AI on June 8, 2026 at 02:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 09 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 08 Jun 2026 01:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in SourceCodester Hospitals Patient Records Management System 1.0. This issue affects some unknown processing of the file /admin/?page=room_types. Performing a manipulation of the argument room results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Title SourceCodester Hospitals Patient Records Management System page room_types cross site scripting
First Time appeared Sourcecodester
Sourcecodester hospitals Patient Records Management System
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:sourcecodester:hospitals_patient_records_management_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester hospitals Patient Records Management System
References
Metrics cvssV2_0

{'score': 3.3, 'vector': 'AV:N/AC:L/Au:M/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 2.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 2.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Hospitals Patient Records Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-06-09T14:42:01.809Z

Reserved: 2026-06-07T09:24:38.279Z

Link: CVE-2026-11468

cve-icon Vulnrichment

Updated: 2026-06-09T14:41:57.415Z

cve-icon NVD

Status : Deferred

Published: 2026-06-08T00:16:42.387

Modified: 2026-06-08T14:57:14.757

Link: CVE-2026-11468

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-08T03:30:16Z

Weaknesses