Unknown · Hospitalmanagement · CVE-2026-102847
**Name of the Vulnerable Software and Affected Versions**
gedelumbung HospitalManagement versions up to c2d45543789a3887067d3915f69d44cfc2cf76a8
**Description**
A flaw in the Guest Book component allows remote exploitation via cross site scripting (XSS), a technique where malicious scripts are injected into trusted websites. The issue exists in the `kirim()` function within the `application/modules/web/controllers/buku tamu.php` file, triggered by the manipulation of the `nama`, `email`, and `pesan` arguments.
**Recommendations**
As a temporary workaround, restrict access to the `kirim()` function in the `application/modules/web/controllers/buku tamu.php` file until a fix is released.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.