Junglewise Threat Intelligence

CVE-2018-25390: HaPe PKH SQL injection in lap-peserta-perdesa-pdf.php

CVE-2018-25390 · Severity: high · CVSS 8.2 · Published 2026-05-29

Technologies: HaPe PKH Project HaPe PKH.

Executive brief

HaPe PKH is a web-based application used for managing social assistance program data. A security flaw in the software allows unauthorized individuals to access and extract sensitive information from the underlying database. This could lead to the exposure of participant records and other private administrative data, potentially impacting the privacy of individuals and the integrity of the program's operations.

Technical details

An SQL injection vulnerability exists in HaPe PKH version 1.1 and earlier due to improper neutralization of special elements in the 'desa' POST parameter within the 'lap-peserta-perdesa-pdf.php' component. An unauthenticated remote attacker can exploit this by sending a specially crafted HTTP POST request containing time-based blind SQL payloads. Successful exploitation allows the attacker to infer and extract sensitive information from the database. Additional vulnerable parameters and endpoints, such as 'nama_kelompok' and various 'id' parameters in the admin interface, have also been identified in public exploit reports.

Affected products

  • HaPe PKH Project HaPe PKH 1.1 and earlier

Timeline

  • 2018-10-12: disclosed: Initial exploit published on Exploit-DB
  • 2026-05-29: advisory: NVD/VulnCheck advisory published

References

Related threats