Sceawere
Vulnerability Detail
CVE-2026-102842UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
KCFinder Unrestricted File Upload Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 1d ago
- Vendor
- gedelumbung
- Product
- HospitalManagement
- Attack Type
- Unrestricted Upload
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affected by this issue is the function app_user_login_model.php::cekUserLogin of the file application/models/app_user_login_model.php of the component KCFinder File Manager. Such manipulation of the argument ADMIN_RS_KCFINDER leads to unrestricted upload. It is possible to launch the attack remotely. The exploit is publicly available and might be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-09-30T01:16:36.373Z",
"pubdate": "2026-09-30T01:16:36.373Z",
"executiveSummary": "A critical security vulnerability exists within the HospitalManagement system, specifically impacting the KCFinder File Manager component integrated via the application/models/app_user_login_model.php file.\nThe vulnerability is categorized as an unrestricted file upload flaw, which permits remote attackers to upload arbitrary files to the host server.\nBy manipulating the ADMIN_RS_KCFINDER argument, an unauthorized actor can bypass intended restrictions, potentially leading to Remote Code Execution (RCE) if the uploaded files are executed by the web server.\nThe risk implication is severe, as successful exploitation provides attackers with full control over the affected application or underlying server environment.\nThe vulnerability is exploitable remotely without requiring authentication in certain configurations, and public exploits are currently available.\nGiven that the project follows a rolling release model and has not responded to vulnerability reports, the system remains in a high-risk state, requiring immediate manual intervention by administrators to mitigate potential exposure.",
"technicalDetails": "The root cause of the vulnerability lies in the improper handling and validation of file upload parameters within the KCFinder File Manager component, specifically invoked through the cekUserLogin function in application/models/app_user_login_model.php.\nThe implementation fails to enforce strict server-side validation on the file types or extensions submitted through the ADMIN_RS_KCFINDER argument. This oversight allows an attacker to transmit malicious payloads, such as PHP web shells, directly to the web server's directory structure.\nThe attack flow initiates when an attacker targets the application's login or file management interface. By injecting or manipulating the ADMIN_RS_KCFINDER parameter, the attacker forces the underlying KCFinder component to process a file upload request without verifying the integrity, content, or extension of the uploaded artifact.\nBecause the component is integrated within the application's authentication model, the flaw is reachable remotely. The web server stores the uploaded file in a directory that is frequently accessible via a browser. Upon successfully uploading a file with an executable extension (e.g., .php, .phtml), the attacker can trigger the execution of the payload by requesting the file path directly via an HTTP request.\nThis behavior facilitates a complete compromise of the web server. The post-exploitation impact includes the ability for the attacker to read, modify, or delete sensitive hospital data, conduct reconnaissance on the internal network, deploy ransomware, or establish persistence within the hosting infrastructure.\nThe lack of input sanitization and the absence of a whitelist-based validation mechanism for file types mean that the system is susceptible to direct weaponization. Since version tracking is absent due to the rolling release nature of the HospitalManagement project, all instances up to commit c2d45543789a3887067d3915f69d44cfc2cf76a8 must be considered inherently vulnerable to this arbitrary file upload vector."
}