PT-2026-95460 · Gedelumbung · Hospitalmanagement
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
gedelumbung HospitalManagement versions up to c2d45543789a3887067d3915f69d44cfc2cf76a8
Description
Improper authentication occurs in the Password Change Handler component due to the manipulation of the
kode user or username arguments. This issue affects the simpan() function within the application/modules/global/controllers/password.php and application/modules/global/controllers/profil.php files. A remote attacker can exploit this flaw to bypass authentication mechanisms.Recommendations
As a temporary workaround, restrict access to the
simpan() function in the application/modules/global/controllers/password.php and application/modules/global/controllers/profil.php files. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hospitalmanagement