CVE-2026-102845
Received Received - Intake

Information Disclosure in gedelumbung HospitalManagement

Vulnerability report for CVE-2026-102845, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: VulDB

Description

A security vulnerability has been detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This issue affects the function error_reporting of the file index.php of the component HTTP Response. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gedelumbung hospitalmanagement to c2d45543789a3887067d3915f69d44cfc2cf76a8 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in gedelumbung HospitalManagement software where the production environment is misconfigured as development mode. This causes detailed error messages including stack traces and SQL errors to be displayed to anyone visiting the site. Attackers can trigger these errors with crafted requests to expose sensitive information like internal file paths, MySQL credentials, and database queries.

Detection Guidance

Check if the HospitalManagement application is running in development mode by inspecting the index.php and database.php files for ENVIRONMENT set to 'development' and db_debug enabled. Look for exposed stack traces or SQL errors in HTTP responses when triggering errors via crafted requests.

Impact Analysis

An attacker could exploit this to gain access to sensitive system details such as database credentials and internal file paths. This information could then be used to launch further attacks against the system, potentially leading to unauthorized data access or system compromise.

Compliance Impact

This vulnerability likely violates compliance requirements for both GDPR and HIPAA due to unauthorized exposure of sensitive data. GDPR requires protection of personal data while HIPAA mandates safeguarding protected health information. The information disclosure could lead to regulatory penalties and legal consequences.

Mitigation Strategies

Set ENVIRONMENT to 'production' in index.php and database.php. Disable db_debug in database.php. Ensure error reporting is configured to suppress sensitive details. Monitor for exposed stack traces or SQL errors in HTTP responses.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102845. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart