Executive brief
HaPe PKH is a web-based application used for managing social assistance program data. A security flaw in the software allows unauthorized individuals to access and extract sensitive information from the underlying database. This could lead to the exposure of participant records and other private administrative data, potentially impacting the privacy of individuals and the integrity of the program's operations.
Technical details
An SQL injection vulnerability exists in HaPe PKH version 1.1 and earlier due to improper neutralization of special elements in the 'desa' POST parameter within the 'lap-peserta-perdesa-pdf.php' component. An unauthenticated remote attacker can exploit this by sending a specially crafted HTTP POST request containing time-based blind SQL payloads. Successful exploitation allows the attacker to infer and extract sensitive information from the database. Additional vulnerable parameters and endpoints, such as 'nama_kelompok' and various 'id' parameters in the admin interface, have also been identified in public exploit reports.
Affected products
- HaPe PKH Project HaPe PKH 1.1 and earlier
Timeline
- 2018-10-12: disclosed: Initial exploit published on Exploit-DB
- 2026-05-29: advisory: NVD/VulnCheck advisory published