CVE-2025-2869

Reflected Cross-Site Scripting (XSS) vulnerability in version 1.0 of the Clinic Queuing System. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the id parameter in /manage_user.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:oretnom23:clinic_queuing_system:1.0:*:*:*:*:*:*:*

History

15 Oct 2025, 16:54

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de Cross Site Scripting (XSS) reflejado en la versión 1.0 de Clinic Queuing System. Esta vulnerabilidad podría permitir que un atacante ejecute código JavaScript en el navegador de la víctima enviando una URL maliciosa a través del parámetro id en /manage_user.php.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
First Time Oretnom23
Oretnom23 clinic Queuing System
References () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-clinic-queuing-system - () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-clinic-queuing-system - Third Party Advisory
CPE cpe:2.3:a:oretnom23:clinic_queuing_system:1.0:*:*:*:*:*:*:*

28 Mar 2025, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-28 11:15

Updated : 2025-10-15 16:54


NVD link : CVE-2025-2869

Mitre link : CVE-2025-2869

CVE.ORG link : CVE-2025-2869


JSON object : View

Products Affected

oretnom23

  • clinic_queuing_system
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')