在 gedelumbung 医院管理系统(截至提交哈希 c2d45543789a3887067d3915f69d44cfc2cf76a8)中发现了一个弱点。该漏洞影响文件 application/modules/admin/controllers/laporan_data_pasien.php 的 detail 功能。通过操纵参数 id_param 可导致越权访问。该漏洞可被远程利用。相关利用代码已公开,可能被用于攻击。该产品未采用版本控制机制,因此无法提供受影响或未受影响版本的相关信息。项目方已通过 issue
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| gedelumbung | HospitalManagement | c2d45543789a3887067d3915f69d44cfc2cf76a8 |
cpe:2.3:a:gedelumbung:hospitalmanagement:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102842 | 6.3 MEDIUM | gedelumbung HospitalManagement KCFinder File Manager app_user_login_model.php cekUserLogin |
| CVE-2026-102845 | 5.3 MEDIUM | gedelumbung HospitalManagement HTTP Response index.php error_reporting information disclos |
| CVE-2026-102843 | 4.7 MEDIUM | gedelumbung HospitalManagement Endpoint data_galeri.php hapus path traversal |
| CVE-2026-102846 | 4.7 MEDIUM | gedelumbung HospitalManagement Configuration sistem.php simpan improper authorization |
No comments yet