Impact
A flaw in the HospitalManagement module allows attackers to manipulate the tipe, title, and content_setting arguments of sistem.php::simpan, resulting in an improper authorization bypass. This gives a remote adversary the ability to alter application configuration without proper authentication or privilege verification.
Affected Systems
The vulnerability affects the HospitalManagement application, specifically the admin configuration handler located in application/modules/admin/controllers/sistem.php. No fixed version is available because the project follows a rolling release model, and the affected releases are only identified by the commit hash c2d45543789a3887067d3915f69d44cfc2cf76a8.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not widely exploited yet. The attack vector is inferred to be remote, as the description states the exploit can be launched remotely. Because the exploit code is public, the threat represents a tangible risk for systems lacking timely remediation.
OpenCVE Enrichment