Junglewise Threat Intelligence

CVE-2018-25386: Sitejo HaPe PKH SQL injection in admin/media.php

CVE-2018-25386 · Severity: high · CVSS 8.2 · Published 2026-05-29

Technologies: Sitejo HaPe PKH.

Executive brief

HaPe PKH is a web-based application used for managing social assistance program data. Multiple security flaws allow attackers to interfere with the application's database, potentially leading to the theft of sensitive information such as user credentials, database names, and system versions. This could result in a complete compromise of the data managed by the platform.

Technical details

Multiple SQL injection vulnerabilities exist in HaPe PKH version 1.1 and earlier due to improper neutralization of special elements in the 'id' parameter within admin/media.php. An unauthenticated attacker can exploit these flaws via the 'desa' module (specifically the 'hapus' action). Additionally, authenticated users can exploit the 'pengurus', 'fasilitas', and 'kelompok' modules through various actions such as 'print' or 'edit'. Successful exploitation allows a remote attacker to execute arbitrary SQL commands, enabling the extraction of sensitive database metadata including the current DBMS user, database name, and version information. No official patch has been identified in the advisory.

Affected products

  • Sitejo HaPe PKH 1.1 and earlier

Timeline

  • 2018-10-12: disclosed: Initial exploit code published on Exploit-DB
  • 2026-05-29: advisory: NVD and VulnCheck advisory published

References