CVE-2026-102846 gedelumbung HospitalManagement 权限不当漏洞
影响攻击者可越权修改系统配置,远程利用
gedelumbung HospitalManagement 的 Configuration Handler 组件中,sistem.php 控制器的 simpan 函数存在权限不当问题。攻击者通过操纵 tipe/title/content_setting 参数即可绕过授权检查。该漏洞利用方式已公开,可被实际利用。
影响范围
影响 gedelumbung HospitalManagement 至提交 c2d45543789a3887067d3915f69d44cfc2cf76a8 的所有版本。该产品采用滚动发布模式,无明确版本号信息。
漏洞详情
漏洞类型为权限不当(Improper Authorization)。成因是 sistem.php 中 simpan 函数未对调用者进行充分的权限校验,导致低权限用户可执行本应受限的配置保存操作。攻击者可远程构造请求,通过操纵 tipe、title、content_setting 参数越权修改系统配置。
利用条件与风险
利用前提是攻击者能够访问相关接口,无需高权限即可发起请求。由于利用代码已公开,实战中被扫描和利用的风险较高。
修复建议
官方尚未发布修复方案,项目方未回应问题报告。临时缓解措施包括限制对 application/modules/admin/controllers/sistem.php 相关接口的访问、加强权限校验或部署 WAF 拦截异常请求。
A vulnerability was detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Impacted is the function sistem.php::simpan of the file application/modules/admin/controllers/sistem.php of the component Configuration Handler. The manipulation of the argument tipe/title/content_setting results in improper authorization. The attack may be launched remotely. The exploit is now public and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.