CVE-2018-25386 HIGH

CVE-2018-25386: HaPe PKH 1.1 SQL Injection via id Parameter in admin/media.php

Vendor Sitejo
Product HaPe PKH
Weakness CWE-89 · SQLi
Published May 29, 2026
Last update May 29, 2026

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

Description

HaPe PKH 1.1 contains multiple SQL injection vulnerabilities in admin/media.php that allow attackers to manipulate database queries by injecting SQL code through the 'id' parameter. An unauthenticated attacker can exploit the desa module (module=desa&act=hapus), while authenticated users can exploit the pengurus, fasilitas, and kelompok modules (for example act=print, act=editpengurus, act=editfasilitas, and act=editkelompok). Successful exploitation allows extraction of sensitive database information including the current user, database name, and DBMS version.

Key dates

Disclosure timeline

May 29, 2026 CVE published
May 29, 2026 Record updated