CVE-2026-102843
Received Received - Intake

Path Traversal in gedelumbung HospitalManagement

Vulnerability report for CVE-2026-102843, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: VulDB

Description

A security flaw has been discovered in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This affects the function hapus of the file application/modules/admin/controllers/data_galeri.php of the component Endpoint. Performing a manipulation of the argument gbr results in path traversal. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gedelumbung hospitalmanagement to c2d45543789a3887067d3915f69d44cfc2cf76a8 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a path traversal flaw in gedelumbung HospitalManagement software. It allows an authenticated admin to delete arbitrary files on the server by manipulating the 'gbr' argument in the hapus function of application/modules/admin/controllers/data_galeri.php. The attack uses path traversal sequences like '../../' to escape the intended directory and target sensitive files.

Detection Guidance

Check for suspicious file deletion attempts in server logs, particularly for requests to the admin/data_galeri/hapus endpoint with path traversal sequences like ../ in the gbr parameter. Monitor for unlink() function calls in application/modules/admin/controllers/data_galeri.php.

Impact Analysis

This vulnerability can lead to denial of service by deleting critical files, potential data loss, and system compromise. Attackers could delete configuration files, databases, or other important system files, disrupting hospital operations and compromising patient data security.

Compliance Impact

This vulnerability could violate compliance with GDPR and HIPAA by enabling unauthorized file deletion and potential data breaches. GDPR requires protecting personal data, while HIPAA mandates safeguarding patient health information. The flaw could lead to unauthorized access or destruction of sensitive data, resulting in regulatory penalties.

Mitigation Strategies

Restrict access to the admin/data_galeri/hapus endpoint to authorized users only. Implement input validation to block path traversal sequences in the gbr parameter. Sanitize file paths before passing them to unlink(). Consider disabling the file deletion functionality temporarily until a patch is available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102843. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart