Home

Description

HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by bypassing file type validation. Attackers can upload PHP files through multiple endpoints including aksi_foto.php, aksi_user.php, and aksi_kecamatan.php to execute arbitrary code on the server.

PUBLISHED Reserved 2026-05-29 | Published 2026-05-29 | Updated 2026-05-29 | Assigner VulnCheck




HIGH: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
HIGH: 8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

Unrestricted Upload of File with Dangerous Type

Product status

1.1
affected

Credits

Ihsan Sencan finder

References

www.exploit-db.com/exploits/45593 (ExploitDB-45593) exploit

www.sitejo.id (Official Product Homepage) product

sourceforge.net/projects/hape-pkh/files/latest/download (Product Reference) product

www.vulncheck.com/...arbitrary-file-upload-via-aksi-foto-php (VulnCheck Advisory: HaPe PKH 1.1 Arbitrary File Upload via aksi_foto.php) third-party-advisory

cve.org (CVE-2018-25388)

nvd.nist.gov (CVE-2018-25388)

Download JSON