CVE-2026-36324

MEDIUM

SourceCodester Doctor Appointment System 1.0 - Stored Cross-Site Scripting in User Registration

Title source: llm
STIX 2.1

Description

SourceCodester Doctor Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) due to improper handling of user supplied input in the user registration functionality in register.php.

Scores

CVSS v3 6.1
EPSS 0.0015
EPSS Percentile 4.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Published May 29, 2026
Tracked Since May 29, 2026