CVE-2026-4617: Sourcecodester Patients Waiting Area Queue Management System

High severity, CVSS 7.3. EPSS: 0.5% chance of exploitation in the next 30 days.

A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. The impacted element is the function ValidateToken of the file /php/api_patient_checkin.php of the component Patient Check-In Module. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.

Affected products

  • Sourcecodester Patients Waiting Area Queue Management System: version 1.0 only

Published 2026-03-24. Last modified 2026-06-17.