Description
A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. This issue affects some unknown processing of the file /patient-search.php. The manipulation results in improper authorization. The attack can be launched remotely. The exploit is now public and may be used.
Published: 2026-03-09
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to patient data
Action: Restrict Access
AI Analysis

Impact

The vulnerability in SourceCodester Patients Waiting Area Queue Management System causes an improper authorization flaw in the patient-search.php page. This flaw allows an attacker to bypass normal access controls and retrieve patient information that should be limited to authenticated users. The impacts could include exposure of sensitive personal health details and potential legal or reputational damage if such data is accessed without permission.

Affected Systems

The flaw affects version 1.0 of SourceCodester Patients Waiting Area Queue Management System. No other versions or vendors are explicitly identified in the available information.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity. EPSS is listed as less than 1%, showing a very low, yet non-zero, likelihood of exploitation. The vulnerability is not currently listed in CISA's KEV catalog. The description states that the attack can be launched remotely, implying that a threat actor could initiate the exploit via web requests to the patient-search.php endpoint, provided no other defensive measures are in place.

Generated by OpenCVE AI on April 16, 2026 at 10:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest version of SourceCodester Patients Waiting Area Queue Management System that addresses this authorization flaw.
  • Restrict direct access to patient-search.php to authenticated users and enforce appropriate role checks in the application logic.
  • Audit application logs for unauthorized access attempts and review access control configurations to ensure alignment with best practices for preventing elevation of privilege and improper access control.

Generated by OpenCVE AI on April 16, 2026 at 10:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 10 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Sourcecodester
Sourcecodester patients Waiting Area Queue Management System
Vendors & Products Sourcecodester
Sourcecodester patients Waiting Area Queue Management System

Mon, 09 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Pamzey
Pamzey patients Waiting Area Queue Management System
CPEs cpe:2.3:a:pamzey:patients_waiting_area_queue_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Pamzey
Pamzey patients Waiting Area Queue Management System

Mon, 09 Mar 2026 12:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Mar 2026 11:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. This issue affects some unknown processing of the file /patient-search.php. The manipulation results in improper authorization. The attack can be launched remotely. The exploit is now public and may be used.
Title SourceCodester Patients Waiting Area Queue Management System patient-search.php improper authorization
Weaknesses CWE-266
CWE-285
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Pamzey Patients Waiting Area Queue Management System
Sourcecodester Patients Waiting Area Queue Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-03-09T11:58:04.316Z

Reserved: 2026-03-08T17:28:05.839Z

Link: CVE-2026-3817

cve-icon Vulnrichment

Updated: 2026-03-09T11:57:54.577Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-09T12:16:11.917

Modified: 2026-03-09T15:03:01.697

Link: CVE-2026-3817

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T10:30:16Z

Weaknesses