Official Product Homepageproduct
http://codekernel.net/ CVE-2020-37240
MEDIUM
Queue Management System 4.0.0 Stored XSS via Add User
Record summary
CVE-2020-37240 has a selected CVSS score of 5.1 (medium); EIP currently links 1 catalogued exploit.
Description
Queue Management System 4.0.0 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through user creation fields. Attackers can insert JavaScript payloads in the First Name, Last Name, and Email fields during user creation, which execute when viewing the User List page.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 18, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Queue Management SystemBrowse Codekernel / Queue Management System | CVE List | 4.0.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBQueue Management System 4.0.0 - _Add User_ Stored XSSExploitDB exploitby Kislay KumarNot analyzed1 file
References
5Product Referenceproduct
https://codecanyon.net/item/queue-management-system/22029961 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-37240 ExploitDB-49296exploit
https://www.exploit-db.com/exploits/49296 VulnCheck Advisory: Queue Management System 4.0.0 Stored XSS via Add UserThird-party advisory
https://www.vulncheck.com/advisories/queue-management-system-stored-xss-via-add-user