---
id: CVE-2020-37240
title: >-
  Queue Management System 4.0.0 contains a stored cross-site scripting
  vulnerability that allows authenticated administrators to inject malicious
  scripts through user creation fields
summary: >-
  Queue Management System 4.0.0 contains a stored cross-site scripting
  vulnerability that allows authenticated administrators to inject malicious
  scripts through user creation fields. Attackers can insert JavaScript payloads
  in the First N…
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
published: '2026-05-16'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T10:10:00.263'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-37240'
references:
  - url: 'http://codekernel.net/'
    label: disclosure@vulncheck.com
  - url: 'https://codecanyon.net/item/queue-management-system/22029961'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/49296'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/queue-management-system-stored-xss-via-add-user
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00243
epssPercentile: 0.13895
ingestedAt: '2026-09-29T10:31:36.287Z'
---

## Overview

Queue Management System 4.0.0 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through user creation fields. Attackers can insert JavaScript payloads in the First Name, Last Name, and Email fields during user creation, which execute when viewing the User List page.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
