CVE-2026-102844

LOW CVSS 4.0: 2.0
Updated Sep 30, 2026
PHP
Parameter Value
CVSS 2.0 (LOW)
Type CWE-285 (Improper Authorization), CWE-639 (Authorization Bypass)
Vendor PHP
Public PoC No

A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This vulnerability affects the function detail of the file application/modules/admin/controllers/laporan_data_pasien.php. Executing a manipulation of the argument id_param can lead to authorization bypass.

The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. This product does not use versioning.

This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
High
Admin privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v4.0