CVE-2026-3724
published 2026-03-08CVE-2026-3724: A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. This impacts an unknown function of the file /checkin.php…
PriorityP359high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.30%
21.8th percentile
A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. This impacts an unknown function of the file /checkin.php. This manipulation of the argument patient_id causes improper authorization. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| pamzey | patients_waiting_area_queue_management_system | — | — |
| pypdf_project | pypdf | >= 0 < 6.10.0 | 6.10.0 |
| sourcecodester | patients_waiting_area_queue_management_system | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.02.1LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
pypdf: Manipulated XMP metadata entity declarations can exhaust RAM
ghsa·2026-04-10
CVE-2026-40260 [MEDIUM] CWE-776 pypdf: Manipulated XMP metadata entity declarations can exhaust RAM
pypdf: Manipulated XMP metadata entity declarations can exhaust RAM
### Impact
An attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing the XMP metadata.
### Patches
This has been fixed in [pypdf==6.10.0](https://github.com/py-pdf/pypdf/releases/tag/6.10.0).
### Workarounds
If you cannot upgrade yet, consider applying the changes from PR [#3724](https://github.com/py-pdf/pypdf/pull/3724).
GHSA
GHSA-987x-fj9w-984x: A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1
ghsa_unreviewed·2026-03-08
CVE-2026-3724 [MEDIUM] CWE-266 GHSA-987x-fj9w-984x: A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1
A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. This impacts an unknown function of the file /checkin.php. This manipulation of the argument patient_id causes improper authorization. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-03-08
Published