PT-2026-102962 · Kcfinder+1 · Kcfinder+1
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
gedelumbung HospitalManagement versions up to c2d45543789a3887067d3915f69d44cfc2cf76a8
Description
A flaw in the KCFinder File Manager component allows remote attackers to perform unrestricted file uploads. This occurs through the manipulation of the
ADMIN RS KCFINDER argument within the cekUserLogin() function located in the application/models/app user login model.php file.Recommendations
As a temporary workaround, restrict access to the
cekUserLogin() function in the application/models/app user login model.php file or avoid using the ADMIN RS KCFINDER argument until a fix is released.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Improper Access Control
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hospitalmanagement
Kcfinder