CVE-2026-102843 HospitalManagement 路径遍历漏洞
影响攻击者可远程读取或删除服务器上的任意文件
gedelumbung HospitalManagement 的 data_galeri.php 控制器中 hapus 函数存在路径遍历漏洞。攻击者通过操纵 gbr 参数可访问预期目录之外的文件。该漏洞 PoC 已公开,可被远程利用。
影响范围
影响 gedelumbung HospitalManagement 至提交 c2d45543789a3887067d3915f69d44cfc2cf76a8 的版本。该项目采用滚动发布,暂无具体受影响或修复版本号公开信息。
漏洞详情
漏洞位于 application/modules/admin/controllers/data_galeri.php 文件的 hapus 函数,该函数未对 gbr 参数进行充分过滤即用于文件路径拼接。攻击者构造包含 ../ 等序列的 gbr 参数即可跳出预期目录,实现路径遍历,读取或删除服务器上的敏感文件。攻击可远程发起,无需本地访问。
利用条件与风险
利用无需认证或仅需低权限(视部署配置而定),且 PoC 已公开,实战风险较高。攻击者可远程读取配置文件、源码等敏感信息,或删除关键文件导致服务异常。
修复建议
官方尚未发布修复版本,建议关注项目仓库更新。临时缓解措施:对 gbr 参数进行严格白名单校验,过滤 ../ 等路径穿越字符,限制文件操作目录范围,并限制该接口的访问权限。
A security flaw has been discovered in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This affects the function hapus of the file application/modules/admin/controllers/data_galeri.php of the component Endpoint. Performing a manipulation of the argument gbr results in path traversal. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.