CVE-2026-3302

A weakness has been identified in SourceCodester Doctor Appointment System 1.0. Affected by this issue is some unknown functionality of the file /register.php of the component Sign Up Page. Executing a manipulation of the argument Email can lead to cross site scripting. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
References
Link Resource
https://github.com/rayficom/Proof-of-Concept/blob/main/20260219/README.md Exploit Third Party Advisory
https://vuldb.com/?ctiid.348053 Permissions Required VDB Entry
https://vuldb.com/?id.348053 Third Party Advisory VDB Entry
https://vuldb.com/?submit.762427 Third Party Advisory VDB Entry
https://www.sourcecodester.com/ Product
Configurations

Configuration 1 (hide)

cpe:2.3:a:remyandrade:doctor_appointment_system:1.0:*:*:*:*:*:*:*

History

27 Feb 2026, 15:36

Type Values Removed Values Added
First Time Remyandrade
Remyandrade doctor Appointment System
CPE cpe:2.3:a:remyandrade:doctor_appointment_system:1.0:*:*:*:*:*:*:*
References () https://github.com/rayficom/Proof-of-Concept/blob/main/20260219/README.md - () https://github.com/rayficom/Proof-of-Concept/blob/main/20260219/README.md - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.348053 - () https://vuldb.com/?ctiid.348053 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.348053 - () https://vuldb.com/?id.348053 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.762427 - () https://vuldb.com/?submit.762427 - Third Party Advisory, VDB Entry
References () https://www.sourcecodester.com/ - () https://www.sourcecodester.com/ - Product

27 Feb 2026, 07:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-27 07:17

Updated : 2026-02-27 15:36


NVD link : CVE-2026-3302

Mitre link : CVE-2026-3302

CVE.ORG link : CVE-2026-3302


JSON object : View

Products Affected

remyandrade

  • doctor_appointment_system
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')