Junglewise Threat Intelligence

CVE-2018-25389: HaPe PKH SQL injection in lap-anggota-kelompok-pdf.php

CVE-2018-25389 · Severity: high · CVSS 8.2 · Published 2026-05-29

Technologies: Insansutejo HaPe PKH. Vendors: Insansutejo.

Executive brief

HaPe PKH, a web-based application used for managing social assistance program data, contains a security flaw that allows unauthorized individuals to access its database. By sending specially crafted requests to the application, an attacker can bypass security controls to view or extract sensitive information. This could lead to the exposure of participant data and administrative records, potentially impacting the privacy of individuals and the integrity of the program's operations.

Technical details

A SQL injection vulnerability exists in HaPe PKH version 1.1 and earlier due to improper neutralization of special elements in the 'nama_kelompok' POST parameter. The flaw is located in the 'lap-anggota-kelompok-pdf.php' component, though additional vectors have been identified in 'lap-peserta-perdesa-pdf.php' and various administrative modules. An unauthenticated remote attacker can exploit this by sending crafted HTTP POST requests containing time-based blind or union-based SQL payloads. Successful exploitation allows the attacker to infer database structures, extract sensitive data (such as user credentials or participant records), and potentially modify database content. No official patch has been confirmed, though the software appears to be an older open-source project.

Affected products

  • insansutejo HaPe PKH (Harian Pendamping PKH) 1.1 and earlier

Timeline

  • 2018-10-12: disclosed: Initial exploit code published on Exploit-DB
  • 2026-05-29: advisory: CVE published and assigned via VulnCheck

References

Related threats