Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-disclosures — CVE-2026-3171 and CVE-2026-3170 vulnerability disclosure by Archana M | Kitploit
Tools/GitHubGitHub/archana1122m/cve-disclosures
Vulnerability AnalysisWeb SecurityPapers & ResearchLearning & EducationCurated Resources
GitHubarchana1122m/cve-disclosures

CVE-disclosures

CVE-2026-3171 and CVE-2026-3170 vulnerability disclosure by Archana M

View Repository
6 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-3171 & CVE-2026-3170 – Archana M

Official vulnerability disclosures by Archana M.


🔹 CVE-2026-3171

Product: SourceCodester / Patrick Mvuma Patients Waiting Area Queue Management System 1.0
Vulnerability Type: Cross-Site Scripting (CWE-79)
Affected File: /queue.php
Attack Vector: Remote
User Interaction: Required
CVSS v3.1: 3.5 (AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N)
Status: Publicly Disclosed

Description

Improper neutralization of user-supplied input (firstname / lastname) leads to a Cross-Site Scripting (XSS) vulnerability.

References

  • https://nvd.nist.gov/vuln/detail/CVE-2026-3171
  • https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3171
  • https://vuldb.com/

  • 🔹 CVE-2026-3170

    Product: SourceCodester / Patrick Mvuma Patients Waiting Area Queue Management System 1.0
    Vulnerability Type: Cross-Site Scripting (CWE-79)
    Affected File: /patient-search.php
    Attack Vector: Remote
    User Interaction: Required
    CVSS v3.1: 2.4 (AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N)
    Status: Publicly Disclosed

    Description

    Improper sanitization of user input (First Name / Last Name) leads to Cross-Site Scripting (XSS).

    References

    • https://nvd.nist.gov/vuln/detail/CVE-2026-3170
    • https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-3170
    • https://vuldb.com/

    👩‍💻 Researcher

    Archana M
    Security Researcher

    Download Tool