CVE-2026-1146 | SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0 api_register_patient.php firstName/lastName cross site scripting
A vulnerability described as problematic has been identified in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this issue is some unknown functionality of the file /php/api_register_patient.php. Such manipulation of the argument firstName/lastName leads to cross site scripting.
This vulnerability is listed as CVE-2026-1146. The attack may be performed from remote. In addition, an exploit is available.