CVE-2025-2868

Reflected Cross-Site Scripting (XSS) vulnerability in version 1.0 of the Clinic Queuing System. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the page parameter in /index.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:oretnom23:clinic_queuing_system:1.0:*:*:*:*:*:*:*

History

15 Oct 2025, 16:55

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
Summary
  • (es) Vulnerabilidad de Cross Site Scripting (XSS) reflejado en la versión 1.0 de Clinic Queuing System. Esta vulnerabilidad podría permitir que un atacante ejecute código JavaScript en el navegador de la víctima enviando una URL maliciosa a través del parámetro page en /index.php.
References () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-clinic-queuing-system - () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-clinic-queuing-system - Third Party Advisory
CPE cpe:2.3:a:oretnom23:clinic_queuing_system:1.0:*:*:*:*:*:*:*
First Time Oretnom23
Oretnom23 clinic Queuing System

28 Mar 2025, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-28 11:15

Updated : 2025-10-15 16:55


NVD link : CVE-2025-2868

Mitre link : CVE-2025-2868

CVE.ORG link : CVE-2025-2868


JSON object : View

Products Affected

oretnom23

  • clinic_queuing_system
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')