CVE-2026-3817 Details
Description
A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. This issue affects some unknown processing of the file /patient-search.php. The manipulation results in improper authorization. The attack can be launched remotely. The exploit is now public and may be used.
An information disclosure vulnerability exists in SourceCodester Patients Waiting Area Queue Management System version 1.0. The issue is located in the file patient-search.php, where the application performs an unrestricted database query. This query embeds the entire patient dataset, including names, dates of birth, phone numbers, and internal identifiers, into a client-side JavaScript variable without any authentication. As a result, unauthenticated remote users can access sensitive patient information.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/HxH404/c4c8e7ce7fe5cde98aca176fba9d7207 | [email protected] | ExploitThird Party Advisory |
| https://vuldb.com/?ctiid.349783 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.349783 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.769535 | [email protected] | Third Party AdvisoryVDB Entry |
| https://www.sourcecodester.com/ | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-285 | Improper Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| pamzey patients waiting area queue management system | 1.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 9, 2026 | Initial Analysis | [email protected] |
| Mar 9, 2026 | New CVE Received | [email protected] |