VYPR

PKH

by HaPe

CVEs (6)

  • CVE-2018-25388HigMay 29, 2026
    risk 0.57cvss 8.8epss

    HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by bypassing file type validation. Attackers can upload PHP files through multiple endpoints including aksi_foto.php, aksi_user.php, and aksi_kecamatan.php…

  • CVE-2018-25390HigMay 29, 2026
    risk 0.53cvss 8.2epss

    HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'desa' POST parameter sent to lap-peserta-perdesa-pdf.php. Attackers can send a crafted request with a time-based blind…

  • CVE-2018-25389HigMay 29, 2026
    risk 0.53cvss 8.2epss

    HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'nama_kelompok' POST parameter sent to lap-anggota-kelompok-pdf.php. Attackers can send a crafted request with a time-based…

  • CVE-2018-25386HigMay 29, 2026
    risk 0.53cvss 8.2epss

    HaPe PKH 1.1 contains multiple SQL injection vulnerabilities in admin/media.php that allow attackers to manipulate database queries by injecting SQL code through the 'id' parameter. An unauthenticated attacker can exploit the desa module (module=desa&act=hapus), while…

  • CVE-2018-25391HigMay 29, 2026
    risk 0.49cvss 7.5epss

    HaPe PKH 1.1 fails to enforce authorization on its record deletion endpoints, allowing unauthenticated attackers to delete arbitrary records by sending a crafted request that specifies the target record's id. The admin/modul/mod_pengurus/aksi_pengurus.php…

  • CVE-2018-25387MedMay 29, 2026
    risk 0.34cvss 5.3epss

    HaPe PKH 1.1 contains a cross-site request forgery vulnerability that allows attackers to change administrator passwords by submitting forged requests to the user update endpoint. Attackers can craft malicious forms targeting the aksi_user.php script with parameters like…