CVE-2026-102847
Received Received - Intake

Cross Site Scripting in gedelumbung HospitalManagement

Vulnerability report for CVE-2026-102847, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: VulDB

Description

A flaw has been found in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. The affected element is the function kirim of the file application/modules/web/controllers/buku_tamu.php of the component Guest Book. This manipulation of the argument nama/email/pesan causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been published and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gedelumbung hospitalmanagement to c2d45543789a3887067d3915f69d44cfc2cf76a8 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored Cross-Site Scripting (XSS) vulnerability in the HospitalManagement system's guest-book form. An attacker can submit malicious JavaScript code in the nama, email, or pesan fields. These inputs are stored in the database without proper sanitization and later executed when an administrator views the guest-book listing or edit page.

Detection Guidance

Check the guest-book form in the HospitalManagement system for unsanitized inputs in the nama, email, or pesan fields. Look for stored JavaScript payloads in the database or HTML output. Review server logs for suspicious submissions containing script tags or event handlers like onmouseover.

Impact Analysis

The vulnerability allows an attacker to steal session cookies if the HttpOnly flag is not set, leading to session hijacking and account takeover. It may also enable defacement of public pages via CKEditor and other malicious actions depending on the attacker's payload.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles and HIPAA's security requirements for protected health information. Non-compliance may result in legal penalties and reputational damage.

Mitigation Strategies

Apply input validation and output encoding to the nama, email, and pesan fields. Sanitize all user inputs before storing them in the database. Implement Content Security Policy (CSP) headers to mitigate XSS impact. Ensure session cookies have the HttpOnly flag set.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102847. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart