CVE-2020-37240 MEDIUM

CVE-2020-37240: Queue Management System 4.0.0 Stored XSS via Add User

Vendor Codekernel
Product Queue Management System
Weakness CWE-79 · XSS
Published May 16, 2026
Last update May 24, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

What the vulnerability does

01Description

Queue Management System 4.0.0 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through user creation fields. Attackers can insert JavaScript payloads in the First Name, Last Name, and Email fields during user creation, which execute when viewing the User List page.

Key dates

02Disclosure timeline

May 16, 2026 CVE published
May 24, 2026 Record updated