Executive brief
HaPe PKH, a web-based application used for managing social assistance data, contains a security flaw that allows users to upload unauthorized files. An attacker with basic login credentials can bypass security checks to upload and run malicious scripts on the server. This could lead to a complete takeover of the system, allowing the attacker to steal sensitive data or disrupt operations.
Technical details
An unrestricted file upload vulnerability (CWE-434) exists in HaPe PKH version 1.1. The application fails to properly validate file extensions or content types across several administrative endpoints, including aksi_foto.php, aksi_user.php, and aksi_kecamatan.php. An authenticated attacker can exploit this by uploading a PHP shell disguised as an image or through direct POST requests. Once uploaded, the script can be accessed via the web root (typically in the /gambar-konten/ directory), leading to remote code execution (RCE) with the privileges of the web server. No patch is currently documented in the advisory.
Affected products
- insansutejo HaPe PKH 1.1
Timeline
- 2018-10-12: disclosed: Exploit published on Exploit-DB
- 2026-05-29: advisory: NVD/VulnCheck advisory published