HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by bypassing file type validation. Attackers can upload PHP files through multiple endpoints including aksi_foto.php, aksi_user.php, and aksi_kecamatan.php to execute arbitrary code on the server.
Metrics
Affected Vendors & Products
References
History
Fri, 29 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by bypassing file type validation. Attackers can upload PHP files through multiple endpoints including aksi_foto.php, aksi_user.php, and aksi_kecamatan.php to execute arbitrary code on the server. | |
| Title | HaPe PKH 1.1 Arbitrary File Upload via aksi_foto.php | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-29T17:25:15.068Z
Reserved: 2026-05-29T11:17:19.632Z
Link: CVE-2018-25388
Updated: 2026-05-29T17:25:09.395Z
Status : Deferred
Published: 2026-05-29T16:16:17.990
Modified: 2026-05-29T16:29:11.350
Link: CVE-2018-25388
No data.
OpenCVE Enrichment
Updated: 2026-05-29T17:30:04Z