Cross Site Scripting Vulnerability in gedelumbung HospitalManagement Software
CVE-2026-102847

5.3MEDIUM

Key Information:

Vendor
CVE Published:
30 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-102847?

A cross site scripting vulnerability has been identified in the gedelumbung HospitalManagement software, specifically within the Guest Book component. This flaw is associated with the manipulation of the parameters 'nama', 'email', and 'pesan' in the 'kirim' function located in the file application/modules/web/controllers/buku_tamu.php. An attacker could exploit this vulnerability to execute arbitrary scripts in the context of a user's browser, potentially leading to unauthorized actions on behalf of the user. It is important to note that remote exploitation is feasible. Despite early notification to the developers regarding this issue, there has been no acknowledged response or patch released to address the vulnerability.

Affected Version(s)

HospitalManagement c2d45543789a3887067d3915f69d44cfc2cf76a8

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chenshiyi (VulDB User)
VulDB CNA Team
.