Cross Site Scripting Vulnerability in gedelumbung HospitalManagement Software
CVE-2026-102847
Key Information:
- Vendor
Gedelumbung
- Status
- Vendor
- CVE Published:
- 30 September 2026
Badges
What is CVE-2026-102847?
A cross site scripting vulnerability has been identified in the gedelumbung HospitalManagement software, specifically within the Guest Book component. This flaw is associated with the manipulation of the parameters 'nama', 'email', and 'pesan' in the 'kirim' function located in the file application/modules/web/controllers/buku_tamu.php. An attacker could exploit this vulnerability to execute arbitrary scripts in the context of a user's browser, potentially leading to unauthorized actions on behalf of the user. It is important to note that remote exploitation is feasible. Despite early notification to the developers regarding this issue, there has been no acknowledged response or patch released to address the vulnerability.
Affected Version(s)
HospitalManagement c2d45543789a3887067d3915f69d44cfc2cf76a8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
