Impact
The vulnerability in SourceCodester Patients Waiting Area Queue Management System causes an improper authorization flaw in the patient-search.php page. This flaw allows an attacker to bypass normal access controls and retrieve patient information that should be limited to authenticated users. The impacts could include exposure of sensitive personal health details and potential legal or reputational damage if such data is accessed without permission.
Affected Systems
The flaw affects version 1.0 of SourceCodester Patients Waiting Area Queue Management System. No other versions or vendors are explicitly identified in the available information.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. EPSS is listed as less than 1%, showing a very low, yet non-zero, likelihood of exploitation. The vulnerability is not currently listed in CISA's KEV catalog. The description states that the attack can be launched remotely, implying that a threat actor could initiate the exploit via web requests to the patient-search.php endpoint, provided no other defensive measures are in place.
OpenCVE Enrichment