HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by bypassing file type validation. Attackers can upload PHP files through multiple endpoints including aksi_foto.php, aksi_user.php, and aksi_kecamatan.php to execute arbitrary code on the server.
History

Sat, 30 May 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Sitejo
Sitejo hape Pkh
Vendors & Products Sitejo
Sitejo hape Pkh

Fri, 29 May 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 29 May 2026 16:15:00 +0000

Type Values Removed Values Added
Description HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by bypassing file type validation. Attackers can upload PHP files through multiple endpoints including aksi_foto.php, aksi_user.php, and aksi_kecamatan.php to execute arbitrary code on the server.
Title HaPe PKH 1.1 Arbitrary File Upload via aksi_foto.php
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-05-29T14:46:32.498Z

Updated: 2026-05-29T17:25:15.068Z

Reserved: 2026-05-29T11:17:19.632Z

Link: CVE-2018-25388

cve-icon Vulnrichment

Updated: 2026-05-29T17:25:09.395Z

cve-icon NVD

Status : Deferred

Published: 2026-05-29T16:16:17.990

Modified: 2026-05-29T16:29:11.350

Link: CVE-2018-25388

cve-icon Redhat

No data.