Sceawere

Vulnerability Detail

CVE-2026-102842UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

KCFinder Unrestricted File Upload Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
1d ago
Vendor
gedelumbung
Product
HospitalManagement
Attack Type
Unrestricted Upload
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affected by this issue is the function app_user_login_model.php::cekUserLogin of the file application/models/app_user_login_model.php of the component KCFinder File Manager. Such manipulation of the argument ADMIN_RS_KCFINDER leads to unrestricted upload. It is possible to launch the attack remotely. The exploit is publicly available and might be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-09-30T01:16:36.373Z",
  "pubdate": "2026-09-30T01:16:36.373Z",
  "executiveSummary": "A critical security vulnerability exists within the HospitalManagement system, specifically impacting the KCFinder File Manager component integrated via the application/models/app_user_login_model.php file.\nThe vulnerability is categorized as an unrestricted file upload flaw, which permits remote attackers to upload arbitrary files to the host server.\nBy manipulating the ADMIN_RS_KCFINDER argument, an unauthorized actor can bypass intended restrictions, potentially leading to Remote Code Execution (RCE) if the uploaded files are executed by the web server.\nThe risk implication is severe, as successful exploitation provides attackers with full control over the affected application or underlying server environment.\nThe vulnerability is exploitable remotely without requiring authentication in certain configurations, and public exploits are currently available.\nGiven that the project follows a rolling release model and has not responded to vulnerability reports, the system remains in a high-risk state, requiring immediate manual intervention by administrators to mitigate potential exposure.",
  "technicalDetails": "The root cause of the vulnerability lies in the improper handling and validation of file upload parameters within the KCFinder File Manager component, specifically invoked through the cekUserLogin function in application/models/app_user_login_model.php.\nThe implementation fails to enforce strict server-side validation on the file types or extensions submitted through the ADMIN_RS_KCFINDER argument. This oversight allows an attacker to transmit malicious payloads, such as PHP web shells, directly to the web server's directory structure.\nThe attack flow initiates when an attacker targets the application's login or file management interface. By injecting or manipulating the ADMIN_RS_KCFINDER parameter, the attacker forces the underlying KCFinder component to process a file upload request without verifying the integrity, content, or extension of the uploaded artifact.\nBecause the component is integrated within the application's authentication model, the flaw is reachable remotely. The web server stores the uploaded file in a directory that is frequently accessible via a browser. Upon successfully uploading a file with an executable extension (e.g., .php, .phtml), the attacker can trigger the execution of the payload by requesting the file path directly via an HTTP request.\nThis behavior facilitates a complete compromise of the web server. The post-exploitation impact includes the ability for the attacker to read, modify, or delete sensitive hospital data, conduct reconnaissance on the internal network, deploy ransomware, or establish persistence within the hosting infrastructure.\nThe lack of input sanitization and the absence of a whitelist-based validation mechanism for file types mean that the system is susceptible to direct weaponization. Since version tracking is absent due to the rolling release nature of the HospitalManagement project, all instances up to commit c2d45543789a3887067d3915f69d44cfc2cf76a8 must be considered inherently vulnerable to this arbitrary file upload vector."
}
CVE-2026-102842: KCFinder Unrestricted File Upload Vulnerability (MEDIUM Severity, CVSS: 6.3) | Sceawere