天下漏洞,尽知其名
MEDIUM

CVE-2026-102842 HospitalManagement KCFinder 不受限上传漏洞

影响攻击者可远程上传任意文件,可能导致服务器被控制

AI 研判

HospitalManagement 是一款医院管理系统,其 KCFinder 文件管理器组件存在不受限上传漏洞。漏洞位于 application/models/app_user_login_model.php 中的 cekUserLogin 函数,攻击者通过操纵 ADMIN_RS_KCFINDER 参数可绕过上传限制。该漏洞 PoC 已公开,且厂商尚未回应。

影响范围

gedelumbung HospitalManagement

受影响版本为 gedelumbung HospitalManagement 截至提交 c2d45543789a3887067d3915f69d44cfc2cf76a8 的版本。由于项目采用滚动发布模式,具体受影响及修复版本号暂无公开信息。

漏洞详情

该漏洞属于不受限文件上传(Unrestricted Upload)类型。成因是 cekUserLogin 函数对 ADMIN_RS_KCFINDER 参数处理不当,未对上传文件的类型、扩展名或内容进行有效校验。攻击者可构造恶意请求上传 WebShell 等危险文件,进而实现远程代码执行。

利用条件与风险

利用前提是目标系统暴露 KCFinder 文件管理功能且攻击者可访问相关接口。由于 PoC 已公开,实战中被扫描和利用的风险较高,可能导致服务器被入侵。

修复建议

官方尚未发布修复版本或补丁,建议关注项目仓库更新。临时缓解措施包括:限制 KCFinder 目录的访问权限、禁止上传可执行脚本文件、对上传目录设置不可执行权限,或暂时下线该组件。

原始情报

A vulnerability was identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affected by this issue is the function app_user_login_model.php::cekUserLogin of the file application/models/app_user_login_model.php of the component KCFinder File Manager. Such manipulation of the argument ADMIN_RS_KCFINDER leads to unrestricted upload. It is possible to launch the attack remotely. The exploit is publicly available and might be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.