Executive brief
The SourceCodester Doctor Appointment System, a web platform for managing medical bookings, contains a security flaw in its user registration process. An attacker can submit malicious scripts during registration that are later executed when an administrator views the user list. This could allow an attacker to hijack administrative sessions, steal sensitive data, or perform unauthorized actions on the platform.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in register.php of SourceCodester Doctor Appointment System 1.0. The application fails to properly sanitize or encode user-supplied input in fields such as first name, last name, and email during the registration process. This malicious input is stored in the database and subsequently rendered without output encoding in the administrative user management interface (admin/users.php). A remote, unauthenticated attacker can exploit this to execute arbitrary JavaScript in the context of an administrator's browser session, which may lead to session hijacking or full administrative account takeover.
Affected products
- SourceCodester Doctor Appointment System 1.0
Timeline
- 2026-05-29: disclosed: Initial disclosure and CVE assignment
- 2026-05-29: advisory: NVD publication date