天下漏洞,尽知其名
MEDIUM

CVE-2026-102845 HospitalManagement 信息泄露漏洞

影响远程攻击者可获取敏感信息

AI 研判

gedelumbung HospitalManagement 的 index.php 中 error_reporting 函数处理存在信息泄露漏洞,攻击者可远程触发并获取敏感信息。该漏洞利用方式已公开,可能被实际利用。项目采用滚动发布模式,暂无具体受影响版本信息。

影响范围

gedelumbung HospitalManagement

受影响版本为 gedelumbung HospitalManagement 截至提交 c2d45543789a3887067d3915f69d44cfc2cf76a8 的版本;因采用滚动发布,暂无具体版本范围公开信息。

漏洞详情

漏洞位于 index.php 中 error_reporting 函数相关的 HTTP 响应处理逻辑,错误信息可能被直接输出到响应中,导致路径、配置等敏感信息泄露。攻击者可远程构造请求触发错误,从而读取这些信息。该漏洞利用代码已公开。

利用条件与风险

攻击者可远程发起利用,无需认证,利用门槛较低;泄露的信息可能为进一步攻击提供便利,但单独利用危害有限。

修复建议

官方尚未回应,暂无公开修复方案;建议关闭生产环境错误显示、限制错误信息输出,并关注项目后续更新。

原始情报

A security vulnerability has been detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This issue affects the function error_reporting of the file index.php of the component HTTP Response. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.