Impact
The KCFinder File Manager component in gedelumbung HospitalManagement contains a flaw in the app_user_login_model.php::cekUserLogin function where the ADMIN_RS_KCFINDER argument is improperly validated, allowing an authenticated user to upload arbitrary files. This input validation weakness (CWE-434) combined with insufficient access control (CWE-284) can enable an attacker to upload and potentially execute malicious code from the web server, thereby compromising confidentiality, integrity, and availability. The vulnerability is exploitable remotely and public proof‑of‑concept code exists.
Affected Systems
The issue affects all instances of gedelumbung HospitalManagement up to commit c2d45543789a3887067d3915f69d44cfc2cf76a8, specifically the KCFinder File Manager in the application/models/app_user_login_model.php file. No formal version numbers are provided because the project uses a rolling release model, meaning every deployment prior to the patch commit is potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The exploit probability metric (EPSS) is not available, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the existence of a published exploit and the ability for attackers to trigger the flaw remotely via the web interface raise the likelihood that this vulnerability may be used in the wild. The risk is significant enough to warrant immediate attention, especially for environments that rely on KCFinder as a file manager.
OpenCVE Enrichment