CVE-2026-3817
MEDIUMPatients Waiting Area Queue 1.0 - Auth Bypass
Title source: llmDescription
A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. This issue affects some unknown processing of the file /patient-search.php. The manipulation results in improper authorization. The attack can be launched remotely. The exploit is now public and may be used.
References (5)
Scores
CVSS v3
5.3
EPSS
0.0003
EPSS Percentile
8.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Classification
CWE
CWE-266
CWE-285
Status
published
Affected Products (1)
pamzey/patients_waiting_area_queue_management_system
Timeline
Published
Mar 09, 2026
Tracked Since
Mar 09, 2026