Clinic's Patient Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via patients.php.