Executive brief
HaPe PKH is a web-based application used for managing social assistance program data. Multiple security flaws allow attackers to interfere with the application's database, potentially leading to the theft of sensitive information such as user credentials, database names, and system versions. This could result in a complete compromise of the data managed by the platform.
Technical details
Multiple SQL injection vulnerabilities exist in HaPe PKH version 1.1 and earlier due to improper neutralization of special elements in the 'id' parameter within admin/media.php. An unauthenticated attacker can exploit these flaws via the 'desa' module (specifically the 'hapus' action). Additionally, authenticated users can exploit the 'pengurus', 'fasilitas', and 'kelompok' modules through various actions such as 'print' or 'edit'. Successful exploitation allows a remote attacker to execute arbitrary SQL commands, enabling the extraction of sensitive database metadata including the current DBMS user, database name, and version information. No official patch has been identified in the advisory.
Affected products
- Sitejo HaPe PKH 1.1 and earlier
Timeline
- 2018-10-12: disclosed: Initial exploit code published on Exploit-DB
- 2026-05-29: advisory: NVD and VulnCheck advisory published