Sourcecodester · Hospital'S Patient Records Management System · CVE-2026-9564
**Name of the Vulnerable Software and Affected Versions**
SourceCodester/oretnom23 Hospitals Patient Records Management System version 1.0
**Description**
Remote exploitation is possible through cross site scripting (XSS), a technique where malicious scripts are injected into trusted websites. The issue occurs in the `/admin/?page=patients/view patient` endpoint when manipulating the `Remarks` variable.
**Recommendations**
Update SourceCodester/oretnom23 Hospitals Patient Records Management System version 1.0 to a version that contains a fix, or avoid using the `Remarks` variable in the `/admin/?page=patients/view patient` endpoint until the issue is resolved.