Impact
The vulnerability allows an attacker to inject malicious script by submitting specially crafted values for the first name or last name fields in patient-search.php. This reflected cross‑site scripting can execute arbitrary code in the victim’s browser, enabling session hijacking, data theft, or site defacement.
Affected Systems
Patrick Mvuma and SourceCodester supply the Patients Waiting Area Queue Management System. The affected version is 1.0, as identified by the CPE string.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, and the EPSS score of less than 1% suggests a low current probability of exploitation. The issue is not listed in KEV. An attacker can reach the vulnerable endpoint remotely by sending crafted HTTP requests; no special privileges are required on the target system.
OpenCVE Enrichment