PT-2026-95460 · Gedelumbung · Hospitalmanagement

·

CVE-2026-93532

·

Published

2026-09-18

·

Updated

2026-09-22

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions gedelumbung HospitalManagement versions up to c2d45543789a3887067d3915f69d44cfc2cf76a8
Description Improper authentication occurs in the Password Change Handler component due to the manipulation of the kode user or username arguments. This issue affects the simpan() function within the application/modules/global/controllers/password.php and application/modules/global/controllers/profil.php files. A remote attacker can exploit this flaw to bypass authentication mechanisms.
Recommendations As a temporary workaround, restrict access to the simpan() function in the application/modules/global/controllers/password.php and application/modules/global/controllers/profil.php files. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93532

Affected Products

Hospitalmanagement