Description
A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. The impacted element is the function ValidateToken of the file /php/api_patient_checkin.php of the component Patient Check-In Module. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.
Problem types
Incorrect Privilege Assignment
Product status
Timeline
| 2026-03-23: | Advisory disclosed |
| 2026-03-23: | VulDB entry created |
| 2026-03-23: | VulDB entry last update |
Credits
Abhiram T (VulDB User)
References
vuldb.com/?id.352481 (VDB-352481 | SourceCodester Patients Waiting Area Queue Management System Patient Check-In api_patient_checkin.php ValidateToken improper authorization)
vuldb.com/?ctiid.352481 (VDB-352481 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.775747 (Submit #775747 | SourceCodester Patients Waiting Area Queue Management System 1.0 Improper Access Controls)
gist.github.com/HxH404/0ab53ccba44456b5400a5908414f5ab1
www.sourcecodester.com/