CVE-2026-102842
Received Received - Intake

Unrestricted File Upload in gedelumbung HospitalManagement

Vulnerability report for CVE-2026-102842, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: VulDB

Description

A vulnerability was identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affected by this issue is the function app_user_login_model.php::cekUserLogin of the file application/models/app_user_login_model.php of the component KCFinder File Manager. Such manipulation of the argument ADMIN_RS_KCFINDER leads to unrestricted upload. It is possible to launch the attack remotely. The exploit is publicly available and might be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
gedelumbung hospitalmanagement to c2d45543789a3887067d3915f69d44cfc2cf76a8 (exc)
kcfinder kcfinder to c2d45543789a3887067d3915f69d44cfc2cf76a8 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an unrestricted file upload flaw in gedelumbung HospitalManagement. The KCFinder file manager is force-enabled for all authenticated users, bypassing its default security settings. The system fails to properly validate file extensions, allowing dangerous types like .php5, .pht, or .phar to be uploaded. The upload directory is web-accessible, enabling attackers to upload and execute malicious PHP files remotely.

Detection Guidance

Check for unauthorized PHP files in web-accessible directories like ../../content_upload. Look for files with extensions such as .php, .php5, .pht, .phar, .inc, .htm, or .htaccess. Monitor logs for unexpected file uploads or execution attempts.

Impact Analysis

An attacker could exploit this to upload malicious files, leading to remote code execution (RCE) on the server. This could allow full control over the system, unauthorized data access, or database compromise. Attackers might also establish persistence by uploading .htaccess files, maintaining access even after patches.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection standards like GDPR and HIPAA. Unrestricted file uploads risk unauthorized data exposure, breaching confidentiality and integrity. It could lead to data breaches, unauthorized access, and failure to implement adequate security controls, resulting in regulatory penalties.

Mitigation Strategies

Disable KCFinder file manager for all users immediately. Implement strict file upload restrictions by blocking executable file extensions and enabling MIME-type verification. Restrict web access to the upload directory and scan for any already uploaded malicious files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102842. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart