CVE-2026-93532 | gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8 Password Change password.php simpan kode_user/username improper authentication
A vulnerability, which was classified as critical, was found in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This issue affects the function application/modules/global/controllers/password.php::simpan/application/modules/global/controllers/profil.php::simpan of the file application/modules/global/controllers/password.php of the component Password Change Handler. Such manipulation of the argument kode_user/username leads to improper authentication.
This vulnerability is traded as CVE-2026-93532. The attack may be launched remotely. Furthermore, there is an exploit available.
This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More