Description
HaPe PKH 1.1 contains a cross-site request forgery vulnerability that allows attackers to change administrator passwords by submitting forged requests to the user update endpoint. Attackers can craft malicious forms targeting the aksi_user.php script with parameters like id_user, password, and level to modify admin credentials without authentication.
Problem types
Cross-Site Request Forgery (CSRF)
Product status
Credits
Ihsan Sencan
References
www.exploit-db.com/exploits/45591 (ExploitDB-45591)
www.sitejo.id (Official Product Homepage)
sourceforge.net/projects/hape-pkh/files/latest/download (Product Reference)
www.vulncheck.com/...-site-request-forgery-via-aksi-user-php (VulnCheck Advisory: HaPe PKH 1.1 Cross-Site Request Forgery via aksi_user.php)