PT-2026-102962 · Kcfinder+1 · Kcfinder+1

·

CVE-2026-102842

·

Published

2026-09-30

·

Updated

2026-09-30

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions gedelumbung HospitalManagement versions up to c2d45543789a3887067d3915f69d44cfc2cf76a8
Description A flaw in the KCFinder File Manager component allows remote attackers to perform unrestricted file uploads. This occurs through the manipulation of the ADMIN RS KCFINDER argument within the cekUserLogin() function located in the application/models/app user login model.php file.
Recommendations As a temporary workaround, restrict access to the cekUserLogin() function in the application/models/app user login model.php file or avoid using the ADMIN RS KCFINDER argument until a fix is released. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102842

Affected Products

Hospitalmanagement
Kcfinder