CVE-2025-2869

Reflected Cross-Site Scripting (XSS) vulnerability in version 1.0 of the Clinic Queuing System. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the id parameter in /manage_user.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:oretnom23:clinic_queuing_system:1.0:*:*:*:*:*:*:*

History

15 Oct 2025, 16:54

Type Values Removed Values Added
References () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-clinic-queuing-system - () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-clinic-queuing-system - Third Party Advisory
Summary
  • (es) Vulnerabilidad de Cross Site Scripting (XSS) reflejado en la versión 1.0 de Clinic Queuing System. Esta vulnerabilidad podría permitir que un atacante ejecute código JavaScript en el navegador de la víctima enviando una URL maliciosa a través del parámetro id en /manage_user.php.
First Time Oretnom23 clinic Queuing System
Oretnom23
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CPE cpe:2.3:a:oretnom23:clinic_queuing_system:1.0:*:*:*:*:*:*:*

28 Mar 2025, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-28 11:15

Updated : 2025-10-15 16:54


NVD link : CVE-2025-2869

Mitre link : CVE-2025-2869

CVE.ORG link : CVE-2025-2869


JSON object : View

Products Affected

oretnom23

  • clinic_queuing_system
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')